Law Firm Probes Data Breach at Central Ohio Primary Care Physicians
A ransomware attack by the 'Chaos' group reportedly exposed up to 362 GB of data from a physician group serving 500,000 patients.
A major healthcare provider in Ohio is facing a legal investigation following a significant data breach that may have compromised the personal information of patients and staff. Edelson Lechtzin LLP has launched an investigation into a potential class action regarding the security failure at Central Ohio Primary Care Physicians (COPCP).
The breach is linked to a ransomware attack carried out by a threat actor group known as 'Chaos.' The attack is estimated to have occurred around August 25, 2026, and was reported the following day. The affected organization is a physician-owned group that provides medical services to more than 500,000 patients across the state of Ohio. While the organization has not verified the specific categories of sensitive information exposed, the law firm's investigation specifically targets the exposure of both patient and employee data. Technical estimates of the stolen data volume are substantial, with sources including Breachsense and HookPhish placing the leak between 263 GB and 362 GB.
The Ransomware Threat to Healthcare
This incident occurs amid a broader trend of ransomware groups targeting the healthcare sector. Medical providers are frequent targets because they rely on high-availability systems and manage highly sensitive Protected Health Information (PHI), which attackers leverage for extortion. The 'Chaos' group's involvement highlights the ongoing vulnerability of physician-owned groups; these entities often lack the massive cybersecurity budgets of integrated hospital networks despite managing similarly critical volumes of patient data.
Industry Implications
Healthcare data breaches are uniquely critical because medical records cannot be changed like credit card numbers or passwords. The exposure of PHI creates a long-term risk for identity theft and medical fraud, where attackers use stolen credentials to obtain prescriptions or insurance payouts. For a provider serving half a million people, a breach of this scale creates significant regulatory risk under HIPAA and potential liability for failing to safeguard patient privacy.
Next Steps
As the investigation by Edelson Lechtzin LLP proceeds, the focus will shift to determining exactly what types of data were exfiltrated and whether COPCP provided timely notification to the affected individuals. It remains to be seen if the organization will acknowledge the full extent of the 'Chaos' group's claims or if a settlement will be reached to compensate those whose private information was leaked.