
Russian ransomware group BlackCat, also known as ALPHV, which has been targeting healthcare organizations in recent months, has allegedly targeted Atlanta-based electronic health record vendor NextGen Healthcare on January 17 and demanded ransoms as high as $1.5M, according to reports.
Claiming responsibility, BlackCat published an alleged sample of NextGen data on its extortion site but later took down its NextGen listing for unknown reasons. Meanwhile, a representative purporting to be a part of the ransomware-as-a-service group refused to provide proof that the group has obtained data from NextGen.
A statement by NextGen confirmed that the company is investigating a recent data security incident but did not comment specifically on BlackCat’s alleged involvement. It acknowledged the attack and said that the threat was immediately contained. The company assured that NextGen’s network is secure and all operations are running as usual.
The forensic investigation being conducted by NextGen has not yet turned up any proof that patient data has been accessed or exfiltrated. According to a NextGen spokesperson, the business is aware of this allegation and has been working with top cybersecurity specialists to investigate and address it.
Meanwhile, the Department of Health and Human Services issued a threat brief, warning healthcare organizations about BlackCat, calling it “a relatively new but highly-capable ransomware threat to the health sector.” It asked healthcare organizations to beef up their cybersecurity strategy to account for the threats posed by BlackCat.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543