Ransomware victim disclosure
← All victimsHicare.net Inc.
listed as hicare · Claimed by Nightspire · listed 4 months ago
Status timeline
- ListedFeb 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Feb 28, 2026
About the victim
AI dossier — public-source company profileHicare.net Inc. is a U.S.-based healthcare technology company that develops customized Connected Care Management platforms and solutions for providers, including Remote Patient Monitoring (RPM) and Chronic Care Management (CCM). The company serves physician practices, hospitals, and health systems, enabling continuous patient monitoring and CMS reimbursement optimization. It offers both full-service platforms and tools to help providers build their own care programs.
- Industry
- Remote Patient Monitoring & Chronic Care Management
Attack summary
Severity: critical — Hicare operates in healthcare, handling patient monitoring data (RPM/CCM) that almost certainly constitutes protected health information (PHI) under HIPAA. The disclosed status is 'data_published', indicating regulated medical and patient data has been exfiltrated and released, qualifying as critical severity.The Nightspire ransomware group claims to have attacked Hicare and lists the disclosure status as 'data_published', indicating data was exfiltrated and published. The leak post content is currently unavailable, so specific details about the data published cannot be confirmed.
Data the group says was taken
AI dossier — extracted from the leak post- Patient health records (likely)
- Provider data
- Connected Care Management platform data
- Potentially CMS billing/reimbursement data
What the group claims
Data is not available now.
Sources
- Victim sitewww.hicare.net
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

