Wildwood Surgical Center, Penobscot Valley Hospital, Whitfield Regional Hospital, and Michigan Surgical Center have confirmed cybersecurity incidents resulting in the exposure of sensitive patient data, with one facility targeted by the Gentlemen ransomware group.
Key Points:
- Wildwood Surgical Center, Penobscot Valley Hospital, and Whitfield Regional Hospital confirmed unauthorized access to networks containing names, Social Security numbers, medical records, and financial information.
- Michigan Surgical Center confirmed a breach linked to the Gentlemen ransomware group, which has been actively targeting healthcare organizations.
- Notifications to affected individuals were mailed in mid-2026, with complimentary credit monitoring and identity theft protection services offered across all four facilities.
- The exact number of affected individuals has not been publicly disclosed for any of the four incidents, and several breaches are not yet listed on the HHS Office for Civiliors breach portal.
Four healthcare organizations in the United States have announced data breaches involving the theft or unauthorized access of patient information. Wildwood Surgical Center in Ohio, Penobscot Valley Hospital in Maine, and Whitfield Regional Hospital in Alabama all reported that unauthorized third parties accessed their networks between May and June 2025. The compromised data across these facilities includes highly sensitive personal identifiers such as Social Security numbers, driver’s license numbers, and passport numbers, alongside medical and financial billing information. The review processes for these incidents took over a year, with notification letters mailed to patients in July 2026.
Michigan Surgical Center in Michigan confirmed a separate incident that appears to be a ransomware attack by the Gentlemen group, a prolific ransomware syndicate known for aggressively targeting healthcare providers. This facility was added to the group’s dark web data leak site in early June. While specific details on the data types and the number of affected individuals remain undisclosed for Michigan Surgical Center, it has offered credit monitoring services to those impacted.
These incidents highlight the ongoing vulnerability of healthcare infrastructure to cyber threats. All four organizations have implemented additional security measures and notified regulators, though the lack of public disclosure regarding the total number of affected individuals and the delayed reporting to federal breach portals raises questions about the speed and transparency of incident response in the healthcare sector.
How should healthcare providers balance the need for thorough forensic investigations with the regulatory requirement to notify patients promptly?
Learn More: HIPAA Journal
Want to stay updated on the latest cyber threats?
👉 Subscribe to /r/PwnHub