The Midwest Spine and Brain Institute (MSBI) has notified the public of a data breach that appears to be the result of an attack carried out by the RansomHub gang.

 

What happened

MSBI has recently begun notifying patients of a data breach against one of its vendor companies, 3C Care Systems, which provides healthcare IT services. MSBI posted a data breach notice on behalf of 3C, sharing that an investigation had been conducted and concluded on June 18th, 2026, with notices coming out more recently. While MSBI has not confirmed the number of victims, they shared that the following information had been accessed: names, dates of birth, medical treatment and diagnostic information, prescription information, and health insurance information. Impacted information may vary by individual.

 

Going deeper

The attack has been claimed by the ransomware gang RansomHub, which says it has 100 gigabytes of sensitive data. It’s unclear if MSBI is the only victim, or if RansomHub targeted multiple organizations that use 3C and aggregated the data.

RansomHub claimed it infiltrated 3C’s systems about two years ago, on November 21st, 2024. MSBI and 3C conducted separate investigations, but 3C has not yet released any information on their website, nor has the Department of Health and Human Services (HHS) provided any information. However, this doesn’t necessarily mean the breach hasn’t been reported; it’s possible that 3C or MSBI has reported the breach and HHS has decided not to publicly publish the data.

 

In the know

RansomHub has been a prominent Ransomware-as-a-Service group that first emerged in February, 2024, meaning that the attack against 3C would have been one of their first. Since then, they’ve impacted over 200 organizations around the world, frequently using double extortion tactics. Under this strategy, hackers steal data and then lock the systems by encrypting, rendering it inaccessible. Generally, the malicious group will tell the victim that data will be released once a ransom is paid. This can be a highly effective strategy, since it can halt operations and create stress in healthcare settings. In some cases, only the hackers have the decryption keys, while in others, forensic specialists are able to help organizations access their data.

 

Why it matters

The data breach against MSBI is important for two reasons. First, it's yet another breach against a third-party or vendor organization, showing that these organizations can sometimes be the most vulnerable to attack. Even though 3C is a healthcare IT company, any organization can have security flaws or become vulnerable to malware or phishing. Staying vigilant must be a priority for healthcare organizations and every vendor that handles protected health information (PHI).

Secondly, the incident shows that RansomHub, and their double-extortion tactics, are still impacting organizations, even though their last reported breach took place in 2025. According to CISA’s StopRansomware report, the group has attacked numerous organizations in manufacturing, healthcare, and finance. In fact, in the summer of 2026, Paubox reported that RansomHub likely became inactive, but that doesn’t mean the actors behind the gang disappeared. Instead, it appears that former members moved on to be part of Qilin, which has already attacked nearly 200 organizations since 2022. While ransomware groups can fall and emerge, many of the strategies can be passed along and remain important to understand and defend against.

 

The big picture

It’s not clear why the data breach was revealed so long after it took place, but when it comes to ransomware attacks, there can be a multitude of factors. In many cases, the FBI and other investigators are involved long after the breach, trying to help organizations get their data back, determine whether a ransom should be paid, and helping organizations improve their security. Now that an initial notice has been provided, it’s possible that more information will soon come to light. Following that, it’s also possible that either 3C or MSBI will face legal action or any penalties related to how the incident was handled.

 

FAQs

When do organizations pay ransoms?

Healthcare companies are generally not advised to pay ransoms, as it doesn’t guarantee access to data will be stored or that stolen data won’t be published. It can also lead to an organization being targeted again in the future, as the attack is considered successful by malicious groups. Even though most healthcare organizations won’t pay the ransom, there are many situations when they do, like if they are unable to access their data. Organizations generally don’t publicize if they decided to pay a ransom, although they will occasionally note if they choose not to. MSBI has not said anything regarding a ransom.

 

What is Ransomware-as-a-Service (RaaS)

RaaS is when skilled ransomware attackers sell their services to less tech-savvy criminals, who go on to use the software or attack methods to target other victims. In return, they pay a fee to the service provider.

 

Will MSBI get in trouble for delaying notifications about the breach?

Not necessarily. It’s important to not assume that healthcare organizations are trying to avoid notifications. In many cases, the investigations are drawn out or need to be kept close to the chest for security reasons. It’s possible that the HHS also gave permission for the notification to be delayed.