TechNewsReel
Live

Ransomware Group INC_RANSOM Claims Data Breach at Horizon Eye Care

The North Carolina-based healthcare provider is facing allegations that patient data was compromised in a June 2026 attack.

TechNewsReel Newsroom · September 1, 2026

A potential data breach at Horizon Eye Care, a healthcare provider based in North Carolina, has been reported following claims from a ransomware collective. The incident highlights the ongoing vulnerability of specialized medical practices to targeted cyberattacks.

The breach was reportedly claimed around June 25, 2026, by the ransomware group known as INC_RANSOM. According to reports from cybersecurity and legal tracking services, including BreachSense and ClassAction.org, the group alleges that it has gained unauthorized access to the provider's systems. While the ransomware group claims that Protected Health Information (PHI) was compromised, a formal disclosure from Horizon Eye Care or the U.S. Department of Health and Human Services (HHS) has not yet been issued to confirm the specific nature or volume of the exposed data.

The Rise of Healthcare Targeting

This incident occurs amid a broader trend of ransomware groups targeting healthcare entities. Medical providers are often viewed as high-value targets because they store sensitive, permanent data—such as Social Security numbers and medical histories—that cannot be changed like a password or credit card number. Furthermore, the critical nature of patient care often puts immense pressure on providers to resolve system outages quickly, which attackers leverage to demand higher ransoms.

Implications for Patient Privacy

The potential exposure of PHI represents a significant privacy violation and a breach of HIPAA regulations. When medical data is leaked, patients face heightened risks of identity theft and sophisticated medical fraud, where attackers use stolen records to obtain prescriptions or medical services under another person's identity. Beyond the immediate financial risk, the leak of private health records can lead to long-term personal and professional distress for affected individuals.

Next Steps for Verification

Industry observers are now waiting for a formal notification to be filed with the HHS Office for Civil Rights, which is required for breaches affecting 500 or more individuals. Until such a filing occurs, the full scope of the incident remains unverified. Patients of Horizon Eye Care are encouraged to monitor their medical statements and credit reports for unauthorized activity while the investigation into the INC_RANSOM claims continues.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.