Nephrology Associates Hit by Ransomware Attack, Exposing Sensitive Patient Data
Nephrology Associates, a U.S.-based medical practice specializing in kidney disease treatment, dialysis services, and hypertension management, recently disclosed a significant data breach. The incident, attributed to the ransomware group INSOMNIA, involved unauthorized access to the company’s network between January 17 and April 9, 2026.
The breach was confirmed on July 1, 2026, after an investigation revealed that sensitive patient information had been exfiltrated. On April 5, 2026, INSOMNIA claimed responsibility for the attack, posting details on the Tor network. Nephrology Associates began notifying affected individuals on July 30, 2026.
Exposed data includes:
- Full names
- Dates of birth
- Driver’s license or state ID numbers
- Government identification numbers
- Treatment and diagnosis details
- Health insurance policy information
The law firm Shamis & Gentile P.A. is investigating the breach on behalf of affected patients, who may be eligible for compensation. The incident underscores the ongoing threat of ransomware attacks targeting healthcare providers and the potential risks to patient privacy.
Source: https://www.claimdepot.com/investigations/nephrology-associates-data-breach-2026-c1ae4
NANI - Nephrology Associates of Northern Illinois & Indiana cybersecurity rating report: https://www.rankiteo.com/company/nephrologyassociates
"id": "NEP1785443613",
"linkid": "nephrologyassociates",
"type": "Ransomware",
"date": "1/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'U.S.',
'name': 'Nephrology Associates',
'type': 'Medical Practice'}],
'customer_advisories': 'Notifying affected individuals on July 30, 2026',
'data_breach': {'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Full names',
'Dates of birth',
'Driver’s license or state ID '
'numbers',
'Government identification '
'numbers',
'Treatment and diagnosis details',
'Health insurance policy '
'information']},
'date_detected': '2026-07-01',
'date_publicly_disclosed': '2026-07-30',
'description': 'Nephrology Associates, a U.S.-based medical practice '
'specializing in kidney disease treatment, dialysis services, '
'and hypertension management, recently disclosed a significant '
'data breach. The incident, attributed to the ransomware group '
'INSOMNIA, involved unauthorized access to the company’s '
'network between January 17 and April 9, 2026. The breach was '
'confirmed on July 1, 2026, after an investigation revealed '
'that sensitive patient information had been exfiltrated. On '
'April 5, 2026, INSOMNIA claimed responsibility for the '
'attack, posting details on the Tor network. Nephrology '
'Associates began notifying affected individuals on July 30, '
'2026.',
'impact': {'data_compromised': 'Sensitive patient information',
'identity_theft_risk': 'High'},
'investigation_status': 'Ongoing',
'ransomware': {'data_exfiltration': True, 'ransomware_strain': 'INSOMNIA'},
'references': [{'date_accessed': '2026-04-05',
'source': 'Tor network (INSOMNIA claim)'}],
'regulatory_compliance': {'legal_actions': 'Investigation by Shamis & Gentile '
'P.A.'},
'response': {'communication_strategy': 'Notifying affected individuals',
'third_party_assistance': 'Shamis & Gentile P.A. (law firm)'},
'threat_actor': 'INSOMNIA',
'title': 'Nephrology Associates Hit by Ransomware Attack, Exposing Sensitive '
'Patient Data',
'type': 'Ransomware'}