
Kettering Health, a healthcare provider based in Ohio, recently experienced a major data security breach that significantly impacted its daily operations.
Headquartered in Kettering, Ohio, Kettering Health is a Seventh-day Adventist non-profit organisation that operates hospitals, stand-alone emergency departments, clinics and Kettering College.
In a data security incident notice published on its website, Kettering Health said that on May 20, it experienced a system-wide technology outage that affected its ability to access patient care systems across the organisation.
The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. It also took steps to contain and mitigate the incident and notified relevant law enforcement authorities about the same.
“Elective inpatient and outpatient procedures at Kettering Health facilities have been canceled for today, Tuesday, May 20. These procedures will be rescheduled for a later date and more information will be provided on this as updates are available. In addition, our call center is experiencing an outage and may not be accessible,” Kettering Health said.
In a separate update, the healthcare provider said that it has received “reports that scam calls have occurred from persons claiming to be Kettering Health team members requesting credit card payments for medical expenses.
“It has not been established that these scam calls are connected to the system-wide technology outage,” the healthcare provider added.
In its last update on May 21, Kettering Health said that “procedures are being evaluated on a case-by-case basis based upon collaborative decision-making between care teams, with safety as our highest priority.
“Additionally, if our care teams have patients’ contact information, they will contact patients by phone about rescheduling procedures.”
While the healthcare provider did not share the identity of the threat actors, a ransom note seen by the CNN claims that the Interlock ransomware group is responsible for the incident.
“Your network was compromised, and we have secured your most vital files,” the ransom note says.
The group has threatened to release the allegedly stolen data unless Kettering Health enters into negotiations for an extortion payment.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543