Ransomware victim disclosure
← All victimsVIPP – Vascular and Interventional Center Development and Management Group
listed as VIPPLLC.COM · Claimed by Clop · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileVIPP (Vascular and Interventional Center Development and Management Group) is a physician-led healthcare organization based in California that owns and operates cardiovascular cath labs, surgical facilities, and diagnostic centers. The company specializes in comprehensive vascular and wound care for diabetic patients, with a focus on reducing lower extremity amputations. It employs interventional radiologists, cardiologists, vascular surgeons, and surgical podiatrists, and is described as one of the largest integrated care providers of its kind in California.
- Industry
- Vascular & Interventional Healthcare Services
Attack summary
Severity: critical — VIPP is a multi-site healthcare provider handling sensitive patient medical records and PHI for diabetic and vascular patients. Clop's disclosed status is 'data_published', indicating confirmed exfiltration and release of what is very likely regulated medical and personal data at scale, meeting the threshold for critical severity under HIPAA-covered entities.The Clop ransomware group has listed VIPPLLC.COM under a 'data_published' status, indicating that data exfiltration has occurred and data has been published or is staged for publication. The leak post content was non-informative (a redirect queue page), so specific data types and volumes are not confirmed from the post itself.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Personal health information (PHI)
- Physician and staff records
- Insurance contract data
- Surgical and diagnostic facility records
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

