INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

WindRose Health Network Discloses Data Breach Affecting 33K Individuals

| 2026-10-05 16:49 CRITICAL LOW DATA BREACH CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
On October 5, 2026, WindRose Health Network disclosed a data breach affecting approximately 33,158 individuals in Indiana. The attack is attributed to an unauthorized third party who exploited a previously undisclosed vulnerability in a remote access tool used by one of its vendors, which was discovered on August 4, 2026. The affected patients' data included names, patient ID numbers, health insurance information, dates of service, and provider names, but not medical records. Cybersecurity experts were engaged to investigate the incident, which occurred between August 3 and August 4, 2026. As a result, WindRose Health Network has advised the affected individuals to remain vigilant against identity theft and fraud.
Technical Mitigations AI-generated
• Patch the remote access tool used by vendors to prevent exploitation of previously undisclosed vulnerabilities. • Monitor for suspicious activity on July 18, 2026, and investigate immediately if unauthorized third-party access is detected. • Review files containing patient data stored in affected parts of the network for potential access or copying.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope healthhealth
Incident Timeline
‎June 2, 2026
Threat actors used phishing tactics to target WindRose Health Network's email environment on June 2, 2026.
‎June 9, 2026
Threat actors accessed WindRose Health Network's systems on June 9, 2026.
‎June 16, 2026
WindRose Health Network disclosed a data breach affecting approximately 33,000 individuals after discovering unauthorized access to one of its computer servers on June 16, 2026.
industry Health
‎June 26, 2026
Threat actors, identified as The Gentlemen, a prolific ransomware group, acquired patient data from Camden Family Health's computer network.
organisation Social Security
organisation AHHC
organisation Camden Family Health
‎July 18, 2026
Threat actors accessed the network of Lakes Region Visiting Nursing Association on July 18, 2026.
organisation Medicare
organisation the HHS’ Office for Civil Rights
‎August 4, 2026
Threat actors used a vulnerability to target Advantage Home Health Care, resulting in the potential unauthorized access or copying of patient data affecting 19,851 individuals.
industry Health
organisation Advantage Home Care
organisation Advantage Home Health Care
‎August 13, 2026
Threat actors used unauthorized access to review an account on August 13, 2026.
‎Oct 5, 2026
WindRose Health Network disclosed a cybersecurity incident affecting 33,158 individuals due to an exposed limited patient data.
industry Health
tactic Data Breach
general_metric 33 Individuals
organisation K Individuals Posted
organisation Lakes Region Visiting Nursing Association
organisation WindRose Health Network
organisation Federally Qualified Health Centers
‎between August 3 and August 4, 2026
Threat actors exploited a vulnerability to gain unauthorized network access between August 3 and August 4, 2026.
Intelligence Sources