GENESIS ransomware lists Interim HealthCare of Oklahoma, claims 1TB stolen (2026)
The GENESIS ransomware group listed Interim HealthCare's Oklahoma City and Tulsa operations on its leak site on 10 August 2026, claiming to have exfiltrated about a terabyte of patient and company data.
- Victim
- Interim HealthCare of Oklahoma City
On 10 August 2026, the GENESIS ransomware group added Interim HealthCare of Oklahoma City and its Tulsa operations to its Tor-based leak site, claiming to have stolen roughly one terabyte of data and threatening to publish it within five days unless a ransom was paid. Interim HealthCare is a nationwide home-healthcare, hospice, and medical-staffing franchise; the listing targeted the Oklahoma franchise entities specifically.
What happened
According to GENESIS, the stolen trove spanned medical and clinical records, patient lists, personal data, and internal company files. The claim followed a cybersecurity incident that Interim HealthCare of Oklahoma City had reported to the U.S. Department of Health and Human Services on 31 July 2026 โ the regulatory filing required under HIPAA's breach-notification rule whenever the protected health information of 500 or more individuals is compromised.
The precise number of affected patients had not been posted to the HHS Office for Civil Rights breach portal at the time of the leak-site listing, and Interim HealthCare had not publicly confirmed the volume of data claimed by GENESIS.
Why it matters
Home-healthcare providers hold unusually rich patient records โ clinical histories, insurance details, and identifiers โ while often operating through franchise networks whose cybersecurity maturity varies widely from one location to the next. The Oklahoma listing was later compounded when a second extortion group separately claimed to have hit an Interim HealthCare entity, raising the question of whether the franchise model itself was creating repeatable footholds for attackers across the brand.
Timeline
Interim HealthCare of Oklahoma City reports a cybersecurity incident to the U.S. Department of Health and Human Services, the threshold filing required when 500 or more people's protected health information is affected.
The GENESIS ransomware group lists Interim HealthCare of Oklahoma and Tulsa on its leak site, claiming roughly 1TB of exfiltrated data and threatening to publish it within five days absent a ransom.
Sources
- hipaajournal.comhttps://www.hipaajournal.com/interim-healthcare-ransomware/
- dexpose.iohttps://www.dexpose.io/genesis-ransomware-strikes-interim-healthcare-in-oklahoma-and-tulsa/
- databreaches.nethttps://databreaches.net/2026/08/29/two-different-groups-have-recently-attacked-interim-healthcare-entities-should-other-franchises-be-concerned/