Ransomware victim disclosure
← All victimsHealthcare Highways
listed as healthcarehighways.com · Claimed by Chaos · listed 2 hours ago
Status timeline
- ListedAug 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Chaos
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 4, 2026
About the victim
AI dossier — public-source company profileHealthcare Highways is a medical provider network company that powers high-performance networks connecting health systems, employers, brokers, payors, and members. Operating from Frisco, Texas, the company manages networks of over 12,000 primary care physicians, 69,000 specialists, and 3,000+ facilities/ancillaries, offering cost containment and healthcare access solutions.
- Industry
- Healthcare Network Management & Provider Networks
- Address
- Frisco, Texas, US
Attack summary
Severity: critical — Confirmed exfiltration of 235 GB involving healthcare-related PII and client records at scale. Healthcare Highways processes sensitive member, employer, and provider data across its networks. The company operates in regulated healthcare sector handling personal health information and business data for multiple stakeholder categories.The Chaos group claims to have exfiltrated approximately 235 GB of sensitive company and client records from Healthcare Highways. The group issued a 24-hour ultimatum for ransom negotiation before publishing the data.
Data the group says was taken
AI dossier — extracted from the leak post- company internal records
- client records
- member information
- employer data
- provider network data
- health plan information
What the group claims
WARNING / DATA LEAK NOTICE Target: Healthcare Highways (healthcarehighways.com) Countdown: 24 Hours If corporate representatives do not establish contact via chat within the next 24 hours, a massive internal data cache comprising 235 GB of sensitive company and client records will be p…
Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

