Heart of America Medical Center: Heart of America Data Breach Exposes SSNs and Medical Records

Heart of America Medical Center: Heart of America Data Breach Exposes SSNs and Medical Records

Heart of America Medical Center Suffers Ransomware Attack, Exposing Sensitive Patient Data

Heart of America Medical Center, a nonprofit critical care hospital in Rugby, North Dakota, disclosed a data breach that compromised sensitive personal, financial, and medical information. The hospital, serving the region since 1905, provides emergency care, surgery, rehabilitation, and other healthcare services.

The breach was reported to the Massachusetts Office of Consumer Affairs and Business Regulation on August 5, 2026, though the total number of affected individuals remains undisclosed. Suspicious network activity was first detected on June 12, 2025, and an investigation later confirmed on September 15, 2025, that files containing sensitive data had been accessed.

On August 6, 2025, the ransomware group Embargo claimed responsibility, posting on its dark web portal that it had stolen 800 gigabytes of data from the hospital. The group provided sample screenshots as proof of the theft.

Exposed data included Social Security numbers, medical records, and other protected health information, putting affected individuals at risk of identity theft and fraud.

In response, Heart of America Medical Center is offering 24 months of complimentary credit monitoring to impacted individuals, with enrollment available for 90 days from the date of notification. The hospital has not publicly confirmed whether a ransom was paid.

Source: https://www.claimdepot.com/data-breach/heart-of-america-medical-center-2026

Heart of America Medical Center cybersecurity rating report: https://www.rankiteo.com/company/heart-of-america-medical-center

"id": "HEA1786041196",
"linkid": "heart-of-america-medical-center",
"type": "Ransomware",
"date": "6/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare',
                        'location': 'Rugby, North Dakota, USA',
                        'name': 'Heart of America Medical Center',
                        'type': 'Hospital'}],
 'customer_advisories': 'Offering 24 months of complimentary credit monitoring '
                        'with 90-day enrollment period',
 'data_breach': {'data_exfiltration': '800 gigabytes of data stolen',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Social Security numbers',
                                              'Medical records',
                                              'Protected health information']},
 'date_detected': '2025-06-12',
 'date_publicly_disclosed': '2026-08-05',
 'description': 'Heart of America Medical Center, a nonprofit critical care '
                'hospital in Rugby, North Dakota, disclosed a data breach that '
                'compromised sensitive personal, financial, and medical '
                'information. The ransomware group Embargo claimed '
                'responsibility and posted stolen data on its dark web portal.',
 'impact': {'data_compromised': 'Sensitive personal, financial, and medical '
                                'information',
            'identity_theft_risk': 'High'},
 'investigation_status': 'Confirmed data breach on 2025-09-15',
 'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Embargo'},
 'references': [{'source': 'Massachusetts Office of Consumer Affairs and '
                           'Business Regulation'}],
 'regulatory_compliance': {'regulatory_notifications': 'Reported to the '
                                                       'Massachusetts Office '
                                                       'of Consumer Affairs '
                                                       'and Business '
                                                       'Regulation'},
 'response': {'communication_strategy': 'Offering 24 months of complimentary '
                                        'credit monitoring to impacted '
                                        'individuals'},
 'threat_actor': 'Embargo',
 'title': 'Heart of America Medical Center Ransomware Attack',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.