Ransomware: anubis claims Interim HealthCare (US) — Healthcare
AI Analysis
On August 15, 2026, the ransomware group Anubis publicly claimed responsibility for a cyberattack against Interim HealthCare, a major US healthcare provider. The claim was published on the ransomware group’s leak site, indicating that the group has exfiltrated data and is likely threatening to release it unless a ransom is paid. This is a public disclosure of a confirmed breach, not a regulatory filing, but it serves as an official notice of a significant security incident affecting a healthcare entity.
The primary affected organization is Interim HealthCare, which operates across the US healthcare sector, including home healthcare, hospice, and staffing services. However, the impact extends to its patients, employees, and business partners, as well as any downstream entities that share data with the provider. Given the healthcare context, this breach likely involves protected health information, which triggers obligations under HIPAA and various state data breach notification laws.
Compliance teams should immediately verify whether their organization has any data-sharing or vendor relationship with Interim HealthCare. If so, they must assess contractual notification requirements and potential downstream exposure. For all healthcare compliance professionals, this is a reminder to review incident response plans, confirm that breach notification timelines are current, and ensure that third-party risk management includes active monitoring of ransomware claims. Finally, update threat intelligence feeds and brief executive leadership on the potential for supply-chain data exposure.
Get notified about BREACH changes
Subscribe to our free weekly digest covering 24 compliance frameworks.