Akira Ransomware Group Claims Attack on Practice Management, Exposing 43GB of Sensitive Data
On September 17, 2026, the ransomware group Akira asserted responsibility for a suspected cyberattack on Practice Management, a healthcare revenue cycle management company based in Illinois. According to reports from dark web monitoring site Ransomware.live, the breach allegedly compromised 43 gigabytes of corporate data, including employee and client personal information.
The attack appears to have occurred on or around the same day the claim was posted, though details about the scope, nature, and confirmation of the breach remain unconfirmed. ClassAction.org, a legal advocacy group, has launched an investigation into the incident, urging current and former employees, as well as patients of Practice Management’s healthcare clients, to come forward if they suspect their data was exposed.
While no official statement from Practice Management has been released, the potential breach raises concerns about privacy violations, financial risks, and operational disruptions for affected individuals. Legal representatives are exploring the possibility of a class action lawsuit to address damages, including lost time, out-of-pocket costs, and identity theft risks.
Cybersecurity analysts continue to monitor the situation as more details emerge. The incident underscores the growing threat of ransomware attacks targeting healthcare-adjacent service providers, which often handle sensitive patient and financial data.
Source: https://www.classaction.org/data-breach-lawsuits/practice-management-september-2026
Practice Management TPRM report: https://www.rankiteo.com/company/practice-management-of-america
"id": "pra1789676746",
"linkid": "practice-management-of-america",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Current and former employees, '
'patients of Practice '
'Management’s healthcare clients',
'industry': 'Healthcare',
'location': 'Illinois',
'name': 'Practice Management',
'type': 'Healthcare revenue cycle management company'}],
'customer_advisories': 'Urging affected individuals to come forward if they '
'suspect their data was exposed',
'data_breach': {'data_exfiltration': 'Allegedly 43GB of data',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Corporate data, employee and '
'client personal information'},
'date_detected': '2026-09-17',
'date_publicly_disclosed': '2026-09-17',
'description': 'The ransomware group Akira asserted responsibility for a '
'suspected cyberattack on Practice Management, a healthcare '
'revenue cycle management company, allegedly compromising 43GB '
'of corporate data, including employee and client personal '
'information.',
'impact': {'brand_reputation_impact': 'Potential privacy violations and '
'financial risks',
'data_compromised': '43GB of corporate data, including employee '
'and client personal information',
'identity_theft_risk': 'High',
'legal_liabilities': 'Possible class action lawsuit'},
'investigation_status': 'Ongoing',
'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Akira'},
'references': [{'date_accessed': '2026-09-17', 'source': 'Ransomware.live'},
{'date_accessed': '2026-09-17', 'source': 'ClassAction.org'}],
'regulatory_compliance': {'legal_actions': 'Possible class action lawsuit'},
'threat_actor': 'Akira',
'title': 'Akira Ransomware Group Claims Attack on Practice Management',
'type': 'Ransomware'}