Ransomware victim disclosure
← All victimsMD Charts
Claimed by Nightspire · listed 4 months ago
Status timeline
- ListedFeb 19, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Feb 19, 2026
About the victim
AI dossier — public-source company profileMD Charts is a U.S.-based healthcare technology company that develops and provides Electronic Medical Records (EMR), Electronic Health Records (EHR), medical billing, and medical coding software. Their platform is HIPAA-compliant and cloud-based, serving healthcare providers across the United States. The company operates at the intersection of health IT and clinical workflow management.
- Industry
- Healthcare IT & Electronic Medical Records Software
Attack summary
Severity: critical — MD Charts handles HIPAA-regulated Electronic Health Records and medical billing data for healthcare providers, meaning any confirmed breach almost certainly involves protected health information (PHI) at scale — a regulated data category warranting critical severity regardless of the currently unavailable proof content.The Nightspire ransomware group claims to have attacked MD Charts and has listed the disclosure status as data_published; however, the leak post content is currently unavailable, preventing confirmation of specific exfiltration or encryption claims.
Data the group says was taken
AI dossier — extracted from the leak post- Patient health records (PHI)
- Electronic medical records
- Medical billing data
- Medical coding data
- HIPAA-regulated personal information
What the group claims
Data is not available now.
Sources
- Victim sitemdchartsehr.com
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

