The home‑health provider has been targeted by two ransomware groups, exposing sensitive patient data and highlighting the growing threat to decentralized healthcare services.

Interim HealthCare, a major provider of home‑health services, confirmed that it was hit by two separate ransomware gangs in a coordinated attack that exposed sensitive patient information and disrupted operations across multiple states.

Dual Threat: Two Gangs, One Target

The first intrusion was attributed to the notorious Genesis ransomware group, which gained initial access through a compromised VPN credential. Within hours, a second group, identified as ShadowLock, leveraged the chaos to deploy its own ransomware payload, encrypting backup files that Genesis had missed.

Both gangs demanded payment in cryptocurrency, threatening to release patient records—including names, medical histories, and billing details—if their demands were not met. Interim HealthCare’s incident response team worked with law enforcement and cybersecurity firms to contain the breach, but the dual nature of the attack complicated mitigation efforts.

Impact on Patients and Services

The breach forced the provider to suspend non‑critical home‑visit appointments in affected regions, leaving vulnerable patients without timely care. While critical services continued, staff had to rely on paper‑based records, increasing the risk of errors and delays.

Patients whose data were compromised were notified via mailed letters and email, with instructions on how to monitor their credit and protect against identity theft. The provider also offered free credit‑monitoring services for a year.

Response and Mitigation Measures

Interim HealthCare engaged a third‑party forensic team to map the attack vectors and purge malicious code. The provider also accelerated its migration to a zero‑trust network architecture, enforcing multi‑factor authentication for all remote access points.

  • Immediate isolation of compromised servers
  • Deployment of endpoint detection and response tools
  • Comprehensive audit of third‑party vendor access
  • Enhanced employee phishing awareness training

The company pledged to review and strengthen its data‑encryption policies, ensuring that patient records are stored in encrypted form both at rest and in transit.

We are deeply sorry for the disruption this incident has caused our patients and partners. Our priority remains restoring full service while safeguarding personal health information.

The attack underscores the growing vulnerability of decentralized healthcare networks, where a dispersed workforce and multiple vendor connections create a larger attack surface for cybercriminals.

Tech Insider coverage of Interim HealthCare ransomware attack