> ## Content Index
> Fetch the complete content index at: https://www.thecybersignal.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Inc Ransom Ransomware Breach at Sandhills Medical Exposes 169,017 Patients — Notified 12 Months Later
- URL: https://www.thecybersignal.com/sandhills-medical-inc-ransom-169000-patients-2026/
- Published: 2026-04-30T14:08:00.000Z
- Updated: 2026-07-15T11:16:14.000Z
- Description: Sandhills Medical Foundation discloses a ransomware breach by Inc Ransom affecting 169,017 patients — nearly 12 months after the attack was detected and 10 months after stolen data was published publicly.
- Author: Nicholas Robert
- Tags: Ransomware, Healthcare Cybersecurity, Data Breaches, PHI (Protected Health Information), PII (Personally Identifiable Information)

*Inc Ransom breached Sandhills Medical Foundation in May 2025, published patient data publicly in June 2025, and affected patients weren't notified until April 2026 — nearly a year later.*

**CHESTERFIELD COUNTY, SOUTH CAROLINA** — Sandhills Medical Foundation discovered a ransomware attack on May 8, 2025\. The organization serves patients across Chesterfield, Kershaw, Lancaster, and Sumter Counties — rural communities with limited access to alternative healthcare providers. The compromised data includes full names, dates of birth, Social Security numbers, Taxpayer Identification Numbers, driver's licenses, government-issued identification, passports, financial information, and personal health information. Inc Ransom listed Sandhills Medical on its leak site in early June 2025 and has since made the allegedly stolen files available for download.

## Breach profile

| Breach Intelligence: Sandhills Medical Foundation |                                                                                                                     |
| ------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------- |
| Detail                                            | Information                                                                                                         |
| Victim                                            | Sandhills Medical Foundation — Federally Qualified Health Center, South Carolina                                    |
| Patients Affected                                 | 169,017 individuals — disclosed to Maine, South Carolina, and Vermont Attorney General offices                      |
| Threat Actor                                      | Inc Ransom ransomware group                                                                                         |
| Attack Detected                                   | May 8, 2025                                                                                                         |
| Dark Web Listing                                  | June 3, 2025 — data published and made available for download on Inc Ransom leak site                               |
| Patient Notifications                             | April 28, 2026 — nearly one year after discovery                                                                    |
| Data Compromised                                  | Names, dates of birth, SSNs, TINs, driver's licenses, passports, financial information, personal health information |

---

### The data: a full identity theft toolkit

The compromised dataset represents a comprehensive identity theft resource. SSNs and TINs enable fraudulent tax filings. Passport data enables international identity fraud. Financial information creates direct account takeover exposure. Personal health information enables insurance fraud. Inc Ransom has published the files publicly, meaning the data is freely accessible to any actor who seeks it. For a broader understanding of how these incidents unfold, see our full explainer on [data breaches: risks, response, and prevention](https://www.thecybersignal.com/data-breaches-understanding-risks-response-prevention/).

### The 12-month notification delay

The gap between attack detection (May 8, 2025) and patient notification (April 28, 2026) — nearly 12 months — is the critical secondary issue. HIPAA's Breach Notification Rule requires notification "without unreasonable delay and in no case later than 60 days" after discovery. With Inc Ransom publishing stolen data publicly in June 2025, affected patients had nearly ten months of unmitigated exposure before receiving official notification. The Sandhills case echoes the delayed disclosure pattern seen in [the Kettering Health ransomware breach](https://www.thecybersignal.com/kettering-health-ransomware-attack-1-7-million-patients-exposed/). 

For comprehensive [healthcare cybersecurity coverage](https://www.thecybersignal.com/tag/healthcare-cybersecurity/), The CyberSignal tracks all major incidents in the sector.

## What to do now

If you are or were a patient of Sandhills Medical Foundation, place a fraud alert or credit freeze with all three major credit bureaus (Equifax, Experian, TransUnion) immediately. Monitor all financial accounts for unusual activity going back to June 2025\. Be vigilant for phishing attempts referencing Sandhills Medical by name. Enroll in the free credit monitoring offered by Sandhills Medical and report any identity theft to the FTC at identitytheft.gov.

---

## The CyberSignal Analysis

### Signal 01 — Rural FQHCs are high-value, low-defense targets

Federally Qualified Health Centers serving rural communities combine sensitive, monetizable data with limited IT security resources. Sandhills Medical serves patients across four South Carolina counties — a patient population that is disproportionately uninsured or underinsured and therefore less likely to have rapid access to fraud remediation services when their data is compromised.

### Signal 02 — A 12-month notification timeline has regulatory consequences

HIPAA's 60-day notification requirement appears to have been significantly exceeded. With Inc Ransom publishing stolen data publicly in June 2025, affected patients had nearly ten months of unmitigated exposure before receiving official notification. Watch for HHS OCR enforcement action.

### Signal 03 — Published data does not expire

The 169,017 affected individuals face fraud risk not just in 2026 but for years to come. SSNs cannot be changed. For rural healthcare providers, this incident illustrates why ransomware is not a recoverable operational disruption — it is a permanent data loss event with ongoing downstream consequences.

---

## Sources

| Type     | Source                                                                                                                                                                                 |
| -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Primary  | [SecurityWeek: Sandhills Medical Says Ransomware Breach Affects 170,000](https://www.securityweek.com/sandhills-medical-says-ransomware-breach-affects-170000/?ref=thecybersignal.com) |
| Official | [Claim Depot: Sandhills Medical Foundation Data Breach — Full Patient Details](https://www.claimdepot.com/data-breach/sandhills-medical-foundation-2026?ref=thecybersignal.com)        |
| Legal    | [Migliaccio and Rathod: Sandhills Medical Data Breach Investigation](https://classlawdc.com/2026/04/29/sandhills-medical-data-breach/?ref=thecybersignal.com)                          |