McLeod Health and Dillon Family Medicine: Dillon Family Medicine Data Breach: PHI and PII Compromised

McLeod Health and Dillon Family Medicine: Dillon Family Medicine Data Breach: PHI and PII Compromised

Dillon Family Medicine Data Breach Exposes Patient Information in South Carolina

Dillon Family Medicine, a McLeod Health-affiliated medical practice in Dillon, South Carolina, disclosed a data breach involving unauthorized access to a server containing sensitive patient information. The incident occurred between October 17 and 18, 2025, when an unauthorized party infiltrated a server that was in the process of being decommissioned.

The breach went undetected for nearly five months until April 14, 2026, when a suspicious file was discovered during the server’s decommissioning. An investigation confirmed the unauthorized access had taken place during the October 2025 window. McLeod Health stated the intrusion was isolated to the single server and did not affect other systems within its network.

On April 25, 2026, the ransomware group Qilin claimed responsibility for the attack, posting on the dark web that it had exfiltrated the organization’s data. The exposed information may include personally identifiable details such as names, dates of birth, and Social Security numbers, as well as protected health information like diagnoses, medications, test results, imaging, health insurance details, and treatment records.

McLeod Health began notifying affected patients on June 4, 2026, via mailed letters and a public notice on its website. The organization also set up a dedicated call center (888-504-8534) for patients seeking further information, available Monday through Friday from 9 a.m. to 9 p.m. ET, excluding major U.S. holidays. The total number of individuals impacted remains undisclosed.

Source: https://www.claimdepot.com/data-breach/dillon-family-medicine-2026

McLeod Health cybersecurity rating report: https://www.rankiteo.com/company/mcleod-health

Mullins First Baptist Church cybersecurity rating report: https://www.rankiteo.com/company/dillon-family-medicine

"id": "MCLDIL1780698551",
"linkid": "mcleod-health, dillon-family-medicine",
"type": "Ransomware",
"date": "10/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare',
                        'location': 'Dillon, South Carolina, USA',
                        'name': 'Dillon Family Medicine',
                        'type': 'Medical Practice'}],
 'attack_vector': 'Unauthorized server access',
 'customer_advisories': 'Dedicated call center (888-504-8534) for affected '
                        'patients, available Monday through Friday from 9 a.m. '
                        'to 9 p.m. ET, excluding major U.S. holidays.',
 'data_breach': {'data_exfiltration': True,
                 'personally_identifiable_information': ['Names',
                                                         'Dates of birth',
                                                         'Social Security '
                                                         'numbers',
                                                         'Health insurance '
                                                         'details'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally identifiable '
                                              'information',
                                              'Protected health information']},
 'date_detected': '2026-04-14',
 'date_publicly_disclosed': '2026-06-04',
 'description': 'Dillon Family Medicine, a McLeod Health-affiliated medical '
                'practice in Dillon, South Carolina, disclosed a data breach '
                'involving unauthorized access to a server containing '
                'sensitive patient information. The incident occurred between '
                'October 17 and 18, 2025, when an unauthorized party '
                'infiltrated a server that was in the process of being '
                'decommissioned. The breach went undetected for nearly five '
                'months until April 14, 2026, when a suspicious file was '
                'discovered during the server’s decommissioning. The '
                'ransomware group Qilin claimed responsibility for the attack, '
                'posting on the dark web that it had exfiltrated the '
                'organization’s data.',
 'impact': {'data_compromised': 'Personally identifiable information and '
                                'protected health information',
            'identity_theft_risk': 'High',
            'systems_affected': 'Single decommissioned server'},
 'initial_access_broker': {'entry_point': 'Decommissioned server'},
 'investigation_status': 'Ongoing',
 'motivation': 'Data exfiltration',
 'post_incident_analysis': {'root_causes': 'Unauthorized access to a '
                                           'decommissioned server'},
 'ransomware': {'data_exfiltration': True, 'ransomware_strain': 'Qilin'},
 'references': [{'source': 'McLeod Health Public Notice'}],
 'regulatory_compliance': {'regulations_violated': ['HIPAA']},
 'response': {'communication_strategy': 'Mailed letters and public notice on '
                                        'website',
              'containment_measures': 'Isolated the affected server'},
 'threat_actor': 'Qilin',
 'title': 'Dillon Family Medicine Data Breach Exposes Patient Information in '
          'South Carolina',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.