Utopia Tech
HealthcareAI-assisted3 min read

Texas Hearing Institute Ransomware Attack Affects 30,000 Patients

Texas Hearing Institute suffered a ransomware attack by the Interlock group affecting 29,744 patients, with 540 GB of data stolen including SSNs, diagnosis information, and financial data. Two additional healthcare breaches were reported: Family Partnerships of Central Florida (8,151 affected by MoneyMessage threat group) and SportsMed Physical Therapy in New Jersey (3,400 affected via email compr

UT

Utopia Tech

August 14, 2026 · 3 min read

Share

Texas Hearing Institute has announced a cybersecurity incident involving the protected health information of almost 30,000 patients. Data breaches have also recently been announced by Family Partnerships of Central Florida and SportsMed Physical Therapy. Texas Hearing Institute The Center for Hearing and Speech, doing business as Texas Hearing Institute, a provider of pediatric audiology services, has notified 29,744 current and former patients about a security incident identified on March 20, 2026.

Suspicious network activity was identified, and immediate action was taken to lock down and secure its environment. Assisted by third-party cybersecurity specialists, Texas Hearing Institute determined on or around April 22, 2026, that certain parts of its network were accessed by an unauthorized third party, including files containing patient information. The list of the affected individuals was finalized on June 19, 2026, and notification letters were mailed on June 26, 2026.

Information potentially compromised in the incident includes names, personal identifiers, Social Security numbers, diagnosis and treatment information, and financial account information. The affected individuals have been offered complimentary single-bureau credit score, credit record, and credit monitoring services. While not mentioned in the breach notification letters, this appears to have been a ransomware attack.

The Interlock ransomware group claimed responsibility and states on its data leak site that 540 GB of data was copied in the attack. Interlock is a ransomware-as-a-service group that steals data and encrypts files, demanding payment for the decryption keys and to prevent the publication of stolen data. The group proceeded to leak the stolen data, indicating the ransom was not paid.

As such, the affected individuals are strongly advised to take advantage of the credit monitoring services being offered. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Family Partnerships of Central Florida Community Based Care of Brevard, doing business as Family Partnerships of Central Florida, a community-based care lead agency contracted by the Florida Department of Children and Families, has notified 8,151 individuals that some of their protected health information has been leaked online.

The MoneyMessage threat group claimed responsibility for the attack. Family Partnerships of Central Florida launched an investigation when it learned about the data leak to determine the nature and scope of the incident. The investigation confirmed that a threat actor had access to its network between December 4, 2025, and January 2, 2026, and exfiltrated files containing names, birth dates, Social Security numbers, driver’s license numbers, state IDs, financial account information, and personal health information.

Since data has been leaked online, the affected individuals have been advised to remain vigilant against identity theft and fraud. The notification letters include information on how they can protect against data misuse. The substitute breach notice does not mention complimentary credit monitoring or identity theft protection services.

Family Partnerships of Central Florida said it is reviewing its policies, procedures, and processes related to the storage and access of sensitive information to reduce the risk of similar incidents in the future. SportsMed PT, New Jersey SportsMed Physical Therapy in Glen Rock, New Jersey, has identified unauthorized access to an employee’s email account. Suspicious activity was identified within the account on May 8, 2026.

The investigation confirmed that the breach was limited to a single email account, which has now been secured. The account was reviewed, and while the investigation into the incident is ongoing, SportsMed Physical Therapy said the exposed data included names in combination with one or more of the following: date of service, provider name, diagnosis information, treatment information, and/or health insurance information.

No actual or attempted misuse of the exposed data has been identified; however, patients have been advised to remain vigilant against identity theft and fraud. The breach was recently reported to the HHS’ Office for Civil Rights as affecting 3,400 individuals. The post Texas Hearing Institute Ransomware Attack Affects 30,000 Patients appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content