
Michigan based healthcare provider Aspire Rural Health System said a data security incident it suffered last year, compromised the sensitive personal information of nearly 140,000 individuals.
Aspire Rural Health System brings together more than 70 healthcare providers serving communities throughout Huron, Lapeer, Sanilac, and Tuscola counties. Its network includes Deckerville Community Hospital, Hills & Dales Healthcare, Marlette Regional Hospital, and The Heartlands Senior Living.
In a data security incident notice filed with the Office of Maine Attorney General, Aspire said that on July 18, it identified unauthorised access within its internal network. The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected network and notified relevant law enforcement authorities about the incident.
“Aspire learned that an unauthorised party gained access to Aspire’s internal network from on or about November 4, 2024, to on or about January 6, 2025,” reads the data security incident notice.
The compromised data included names and other personal identifiers including Social Security numbers. The filing with the Maine state regulator also states that Aspire has identified at least 138,386 individuals impacted by the incident.
While Aspire found no evidence of the compromise data being misused, it has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered one year of complimentary identity protection and credit monitoring services through Experian IdentityWorks to all affected individuals.
Actor : bianlian
— ThreatMon Ransomware Monitoring (@TMRansomMon) February 13, 2025
Victim : Aspire Rural Health System
Date : 2025-02-13 20:57:22 UTC +3
According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#bianlian” Ransomware group has added Aspire Rural Health System to its victims.
The notorious BianLian ransomware group claimed responsibility for the cyber attack on Aspire, listing it as a victim on its data leak site. The group said it had obtained confidential data from the healthcare provider and threatened to release the entire database unless its ransom demands are met.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543