Integris Health, Oklahoma's largest not-for-profit health network, confirms a November cyberattack resulting in stolen data, after patients get extortion emails
Integris Health patients in Oklahoma are receiving blackmail emails stating that their data was stolen in a cyberattack …
BleepingComputerLawrence Abrams
Context & Ripple Effects
Integris Health's confirmation turns patient-received extortion messages into a verified data-theft incident. It fits an established healthcare pattern: a prior Canadian provider breach also left detailed patient records allegedly held for ransom in the CarePartners extortion case.
Later coverage shows the exposure is not confined to a single provider: the Change Healthcare breach's reported scale and a reported intrusion of Cerner servers used to extort providers underscore how patient data can create leverage across healthcare delivery and its technology suppliers.
First-order effects
Patients whose information was taken face targeted extortion attempts and potential ongoing misuse of their data.
Integris Health must manage a confirmed theft incident alongside patient communications prompted by the extortion emails.
Second-order effects
The incident raises the operational and reputational cost for healthcare organizations of protecting patient-data stores, particularly where attackers can contact affected people directly.
Healthcare IT vendors and provider networks face greater pressure to limit the blast radius of compromised systems, as later allegations involving Cerner server theft used for provider extortion illustrate.
Third-order effects
If direct-to-patient extortion continues, healthcare breaches will increasingly be judged by post-intrusion harm to individuals, not solely by whether care systems were disrupted.
The pattern favors blast-radius architecture: separating and constraining access to sensitive records so a single intrusion yields less usable data and fewer downstream victims.
The trend: Healthcare cyberattacks are evolving from system disruption into data-extortion campaigns that exploit the enduring sensitivity and reach of patient records.
Oklahoma has been hit hard with two major hospital systems falling victim in the last two months to ransomware cyberattacks (Hillcrest, Integris). These attacks on hospitals are disruptive to patient care and are threat-to-life crimes. Cybercriminals are often based in Eastern...
@LibertyDrew84 @CrownAndJoke This is my second data breach with Integris. On the first I received a one year free of credit monitoring with Experian, and when I went to claim it, they said i can't even use it bc it's an expired link 👍🏼😒
In a statement, Integris Health confirmed the following patient data may have been compromised: Date of birth, contact and demographic information and social security numbers. https://www.news9.com/...
I think the coolest thing Integris did was to absolutely fucking bury this story, issuing it late on a Sunday that's also Christmas Eve. That was cool.
Woke up thinking about the data breach that occurred from Integris. Something I saw mentioned was the group responsible accessed files... Like are you telling me you just had a folder of .CSV files with all this sensitive data just hanging out on a network share?
Integris Health just confirmed a massive data breach. This blows. Name, address, social security number, all of it. Dude, fuck Integris. This was a known vulnerability for years and they did nothing. Smfh. https://www.newson6.com/...
INTEGRIS Health said it is working to investigate a data breach in which hackers claimed they stole the data of more than 2 million patients to sell on the dark web. https://www.news9.com/...