
NorthBay Health has confirmed a significant data breach that compromised the personal and financial information of approximately 569,012 individuals following a ransomware attack by the Embargo group earlier last year. The disclosure was made in a filing to state regulators in Maine last week, highlighting the extent of the breach that affected the nonprofit healthcare provider’s systems between January 11 and April 1, 2024.
According to reports from The Record, a cybersecurity news site by Recorded Future, the stolen data includes sensitive financial, medical, and health insurance details. Social Security numbers, passport information, and credit or debit card numbers were also accessed during the breach. Embargo, the ransomware group behind the attack, is a relatively new but emerging threat in the cybersecurity landscape.
NorthBay Health first acknowledged the attack in April 2024, describing it as a “cyber incident” on its website. The healthcare provider then stated that it had launched an internal investigation and engaged leading cybersecurity experts to mitigate the impact and restore affected systems. The attack led to temporary disruptions in NorthBay’s services, forcing the provider to cancel appointments and turn patients away.
In response to inquiries on Monday, NorthBay Health reiterated its commitment to investigating the breach and securing its systems. The organization confirmed that it had worked closely with law enforcement and a forensic security firm to assess the extent of unauthorized access. The investigation concluded that a third party had infiltrated specific files within NorthBay Health’s computer systems.
Following the confirmation of the breach, NorthBay Health has sent notifications to affected individuals, offering complimentary identity protection and credit monitoring services. The healthcare provider expressed gratitude for the community’s patience and support as it continues to address the fallout from the attack. “NorthBay Health takes our responsibility to safeguard personal information seriously and thanks the community for its continued patience and support as we have worked to address and investigate the issue,” the statement read.
A company official declined to provide further comments, citing ongoing litigation related to the breach. NorthBay Health operates multiple healthcare facilities in Solano County, California, including NorthBay Health VacaValley Hospital in Vacaville and NorthBay Health Medical Center in Fairfield. In addition, the provider manages several specialty care offices, urgent care locations, and a cancer center, serving a significant portion of the regional population.
© 2025, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543