Ransomware victim disclosure
← All victimsARC Dialysis LLC
Claimed by pear · listed 1 month ago
Status timeline
- Listed
Apr 7, 2026
- Data leaked
At a glance
- Group
- pear
- Status
- Data leaked
- Country
- US
- Sector
- Healthcare
- Listed on leak site
- Apr 7, 2026
About the victim
AI dossier — public-source company profileARC Dialysis LLC is an independent, 100% minority-owned dialysis service provider headquartered in Miami, Florida, and claims to be the largest provider of inpatient dialysis in South Florida. The company delivers acute, outpatient, and in-home dialysis therapies across seven states, serving hospitals, health systems, skilled nursing facilities, and rehabilitation centers. ARC operates twelve free-standing dialysis centers offering in-center, home, and peritoneal dialysis modalities.
- Industry
- Outpatient & Inpatient Dialysis / Kidney Care Services
- Address
- 4960 Southwest 72nd Avenue, Suite 208, Miami, Florida 33155
Attack summary
Severity: critical — ARC Dialysis is a healthcare provider handling sensitive patient medical records including kidney disease treatment data, which constitutes regulated PHI under HIPAA. The disclosed status is 'data_published', indicating actual exfiltration and public release of data affecting patients across seven states and twelve facilities, representing a large-scale breach of sensitive medical information.The ransomware group 'pear' claims to have attacked ARC Dialysis LLC, with the disclosure status indicating data has been published. The specific nature of what was exfiltrated or encrypted is not detailed in the leak post beyond the brief characterization of the victim as an independent dialysis service provider.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Kidney care treatment data
- Patient personal information
- Healthcare facility operational data
What the group claims
Independent dialysis service provider
Sources
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
