
Nearly 20,000 patients were affected by a data security breach that healthcare provider McLeod Health detected earlier this year.
McLeod Health is a not-for-profit healthcare system headquartered in Florence, South Carolina. Established in 1906, it operates a network of hospitals and clinics, including McLeod Regional Medical Center, McLeod Health Dillon, McLeod Health Cheraw, McLeod Health Clarendon, McLeod Health Loris, McLeod Seacoast, and McLeod Health Carolina Forest, providing comprehensive medical services across South Carolina.
In a data security incident notice published on its website, McLeod Health said that on March 5, it discovered a suspicious file on a Dillon Family Medicine server that was being decommissioned. The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.
“On April 14, 2026, we learned through the investigation that an unauthorised party had accessed the server containing Dillon Family Medicine patient information between October 17, 2025 and October 18, 2025. Importantly, this incident was limited to the one server and did not involve any active McLeod Health systems, such as the practice’s current electronic medical record system,” McLeod Health said.
The compromised data included names, dates of birth, Social Security numbers, diagnoses data, medications, test results, images, health insurance, and treatment information.
The incident was reported to the U.S. Department of Health and Human Services where McLeod Health said it has identified at least 19,553 individuals impacted by the incident.
The healthcare provider has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered complimentary identity protection and credit monitoring services to all affected individuals.
At the time of publication, no known threat actor had claimed responsibility for the cyberattack on McLeod Health. The healthcare provider also did not disclose details about the attackers’ identity, the extent of the compromised data, or whether it had received any ransom demands.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543