Ransomware victim disclosure
← All victimsQRS Inc.
listed as QRS Healthcare Solutions · Claimed by Snatch · listed 5 years ago
Status timeline
- ListedNov 30, 2021
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Nov 30, 2021
About the victim
AI dossier — public-source company profileQRS Inc. (also known as QRS Healthcare Solutions) was founded in 1983 to help healthcare providers become profitable and to support their goals of delivering better patient care. The company operates in the healthcare business services sector, providing revenue cycle management and administrative support to medical providers. It emphasizes a service model built on personal relationships with its provider clients.
- Industry
- Healthcare Revenue Cycle Management & Provider Support Services
- Founded
- 1983
Attack summary
Severity: critical — QRS Inc. is a healthcare revenue cycle management firm serving medical providers, meaning exfiltrated data is highly likely to include regulated PII and potentially PHI (Protected Health Information) covered under HIPAA. The disclosed status is 'data_published', confirming actual data release rather than mere listing.The Snatch ransomware group claims to have compromised QRS Inc. and has published data ('data_published' status), indicating exfiltration of company data. The specific categories and volume of data exfiltrated have not been detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Healthcare provider business records
- Financial and billing data
- Patient-related administrative data
What the group claims
QRS INC. was founded in 1983 to help providers become profitable and to support them in their goals of better healthcare for their patients. We are proud of what we do, and we work hard to create a support environment built on personal relationships and
Source
Indexed 5 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

