Sandhills Medical Foundation, a South Carolina healthcare provider, notified patients that a ransomware-related breach exposed the data of 169,017 people after an unauthorized party accessed a server and stole files. The organization said it discovered the incident on May 8, 2025 after system disruptions initially linked to a vendor-related technical issue, and a subsequent forensic investigation determined that data had been exfiltrated from systems affecting select patients.
The compromised information reportedly included sensitive personal, financial, and health data, raising risks of identity theft and medical privacy exposure. The ransomware group Inc later claimed responsibility and added Sandhills to its leak site on May 30, 2025, though Sandhills did not publicly confirm the gang's involvement and said it did not pay a ransom; reporting also noted the case as one of the larger healthcare breaches attributed to the group.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
By late April 2026, Sandhills Medical Foundation publicly disclosed that the May 2025 incident affected 169,017 individuals. The organization said exposed data included sensitive personal, financial, and health information.
On May 30, 2025, the ransomware group Inc claimed responsibility for the Sandhills Medical Foundation breach and posted the organization on its leak site. Sandhills did not publicly confirm Inc's involvement and said it did not pay a ransom.
On May 8, 2025, Sandhills Medical Foundation discovered an incident after system disruptions initially tied to a vendor-related technical issue. A forensic investigation later determined that an unauthorized third party had directly accessed a server and stolen data for certain patients.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.