Ransomware victim disclosure
← All victimsPathology Associates Of Saint Thomas
Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Jan 14, 2026
About the victim
AI dossier — public-source company profilePathology Associates Of Saint Thomas (PAST Nashville) is a pathology and clinical laboratory services provider based in Nashville, Tennessee, United States. The organization is associated with Saint Thomas Health and provides diagnostic pathology services to healthcare facilities and patients. As a healthcare sector entity, it handles sensitive medical and patient data.
- Industry
- Medical Laboratory & Pathology Services
Attack summary
Severity: critical — The victim is a medical pathology laboratory in the US healthcare sector handling regulated patient data (PHI/PII) subject to HIPAA. The disclosure status is 'data_published', indicating confirmed exfiltration and public release of likely sensitive medical and personal health information at scale.The Qilin ransomware group has listed Pathology Associates Of Saint Thomas under a disclosed/data-published status, claiming to have obtained and published data from the organization. The specific nature of exfiltrated data and any encryption activity are not detailed in the truncated leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Pathology/diagnostic reports
- Personal health information (PHI)
- Employee records
- Billing and financial data
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

