
US healthcare network Prospect Medical Holdings said a recent cyber security incident it suffered compromised the personal information of more than 190,000 individuals.Prospect Medical Holdings is one of the largest hospital networks in the US with 16 hospitals under its wing operating in California, Connecticut, Pennsylvania, and Rhode Island. It also runs a network of 166 outpatient clinics and centres.The news of a cyber attack came to light when the internal systems connected to the hospital’s network started facing technical issues, forcing hospitals to divert patients to other facilities and to put a temporary halt to operations.In a statement shared with the media, a Prospect Medical Holdings’ spokesperson confirmed the news of a cyber attack, stating that the hospital chain suffered a “data security incident that has disrupted our operations.”“Upon learning of this, we took our systems offline to protect them and launched an investigation with the help of third-party cyber security specialists. While our investigation continues, we are focused on addressing the pressing needs of our patients as we work diligently to return to normal operations as quickly as possible,” the spokesperson added.The notorious Rhysida ransomware gang claimed responsibility for the cyber attack on the hospitals’ network and listed Prospect as a victim on its data leak site. The group claimed to be in possession of sensitive personal data of more than half a million PMH patients and employees that includes social security numbers, passports, driver’s licenses, patient medical files, and legal and financial documents. “Introducing our new partners – Prospect Medical Holdings....If you are interested in our partner’s confidential documents, you will be able to purchase them too!!! Total 1TB unique files, as well as 1.3TB SQL database,” Rhysida posted.“With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner!” the group added.The group also posted sample data that contained Social Security Numbers and passport copies to prove the authenticity of the data. The group offered to sell the stolen data for a price of 50 Bitcoins and set up a timer of 9 days from the date of the post, which expired on September 1.In a recent filing with the Office of the Maine Attorney General, Prospect Medical Holdings disclosed that the security incident has compromised the sensitive personal information of at least 190,492 individuals.Prospect said the compromised information included patients’ names and other personal identifiers such as Social Security Numbers. The company is providing a year of complimentary credit monitoring and identity theft protection services via IDX to all the individuals whose data has been compromised during the breach. It has also set up a dedicated helpline where impacted individuals can call and get their queries answered.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543