Ransomware victim disclosure
← All victimsHealthcare Solutions Team (HST), operating as Claritev
listed as Hst · Claimed by Thegentlemen · listed 1 day ago
Status timeline
- ListedAug 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Aug 7, 2026
About the victim
AI dossier — public-source company profileHealthcare Solutions Team (HST), now operating as Claritev, is a US-based healthcare cost-containment company specializing in value-driven health plans, reference-based pricing solutions, and patient advocacy. The company operates the HST Care Connect portal to help employers and individuals identify quality healthcare providers and optimize medical benefits.
- Industry
- Healthcare Cost Containment & Health Plan Management
Attack summary
Severity: high — Confirmed data publication involving a healthcare company with access to health plans, provider networks, and potentially sensitive patient/employer medical benefit information. Healthcare sector data is regulated (HIPAA) and carries inherent sensitivity.The threat actor claims access to HST/Claritev infrastructure and has published data from the breach. The post does not explicitly state whether data was encrypted, exfiltrated, or both.
Data the group says was taken
AI dossier — extracted from the leak post- Healthcare provider networks
- Health plan information
- Patient advocacy records
- Medical benefit data
- Employer health plan details
What the group claims
hstechnology.com zoominfo.com/c/hst/352516154 digital platform for Healthcare Solutions Team (HST), a US-based healthcare cost-containment company now operating as Claritev. The company specializes in value-driven health plans, reference-based pricing solutions, and patient advocacy to reduce medical expenses. Through its HST Care Connect portal, it helps employers and individuals seamlessly find quality healthcare providers and optimize their medical benefits
Sources
- Victim sitehstechnology.com
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

