Ransomware victim disclosure
← All victimsmyLaurel Health
listed as myLaurel · Claimed by Direwolf · listed 4 hours ago
Status timeline
- ListedSep 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Sep 6, 2026
About the victim
AI dossier — public-source company profilemyLaurel Health is a US-based home-visit healthcare and recovery-at-home (RAH) care-coordination operator providing registered nurse (RN) field visits scheduled through their CareDash CRM platform for partner health systems and insurance plans including Maimonides, Centerlight, Emblem, ArchCare, Ochsner, and PHN.
- Industry
- Healthcare Services & Care Coordination
Attack summary
Severity: critical — Confirmed exfiltration of comprehensive healthcare PII at massive scale (6.8M+ rows, 6.4 GB). Includes full patient demographics, dates of birth, addresses, phone numbers, insurance data, and clinical information (episodes, chief complaints, visit records) spanning multiple patient cohorts across major NY/regional health systems. Sensitive regulated healthcare data under HIPAA; presence of Healthix EMPI HIE identifiers amplifies re-identification risk.The direwolf group claims to have exfiltrated myLaurel Health's complete operational and clinical databases, totaling approximately 6.4 GB across 160 JSONL files and 3 database exports containing 6,813,905 rows of data. The breach includes 7+ years of scheduling, clinical, insurance, and patient records spanning 2019–2026.
Data the group says was taken
AI dossier — extracted from the leak post- Patient demographics and PII (51,487+ records)
- Home visit records with addresses and provider details (58,317 records)
- Referral intake forms with full patient information (140,711 records)
- Insurance and payer/plan data (35,602 records)
- Phone numbers and emergency contacts (22,955+ records)
- Clinical episodes and care reviews (34,244+ records)
- athenahealth clinical claims and medical documents
- Jotform screening and consent forms (2025–2026)
- Genesys call center logs with caller/callee data (151,668 records)
- EMR identifiers (athenaPatientId, athenaDepartmentId, Healthix EMPI HIE identifiers)
- Patient dates of birth, race, ethnicity, language, housing/marital status
- Provider triage and chief complaint notes
- Scheduling tickets and visit disposition logs (1,602,130+ records)
What the group claims
Elderly Care Services
The leak post
captured from the group's site```
{"article":{"id":123,"title":"myLaurel","content":"\u003ch1\u003eData Warehouse Briefing\u003c/h1\u003e\n\u003ch2\u003e1. Overview\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eItem\u003c/th\u003e\n\u003cth\u003eValue\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eBusiness\u003c/td\u003e\n\u003ctd\u003e\u003cstrong\u003emyLaurelHealth\u003c/strong\u003e (US home-visit healthcare \u0026amp; \u0026#34;Recovery at Home\u0026#34; (RAH) care-coordination operator: RN field visits (types RNI/RNF) scheduled through CareDash CRM for partner health systems/plans - MAIMONIDES, CENTERLIGHT, EMBLEM, ARCHCARE, Ochsner, PHN; evidence: @mylaurelhealth.com / @contractor.mylaurelhealth.com emails, partner.axlehealth.com visit URLs, athenaPatientId/athenaDepartmentId EMR keys, myLaurel LA (Louisiana) consent forms, NY addresses \u0026amp; 504/718/347 phone numbers)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eTotal size\u003c/td\u003e\n\u003ctd\u003e~6.4 GB on disk (~6.8 GB apparent), 160 JSONL table files, \u003cstrong\u003e3 database exports\u003c/strong\u003e, \u003cstrong\u003e6,813…Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

