2026 FMRS Health Systems — Jan 20–Feb 27 file copy; Qilin claim; OCR ≥500 (ongoing)
Data compromised
Names plus address, DOB, SSN, DL, financial account info, medical history, diagnostic/treatment, prescriptions, physician name, MRN, health insurance (per substitute notice field list)
Technical writeup
Verified FMRS Health Systems substitute notice / OCR filing summarized September 2026 (HIPAA Journal). Suspicious activity identified Feb 27, 2026; unauthorized access window Jan 20–Feb 27; files copied; electronic medical records not accessed. OCR filing at least 500 individuals with investigation ongoing (tally may rise). Qilin ransomware group claimed the attack. recordsAffected 500 as OCR floor; companyConfirmed true.
Root cause
Unauthorized access Jan 20–Feb 27 2026; files containing patient information copied (EMR not accessed per notice). Qilin claimed responsibility.