Ransomware victim disclosure
← All victimsWest County Health Centers
Claimed by Storm · listed 4 hours ago
Status timeline
- ListedSep 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Storm
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Sep 30, 2026
About the victim
AI dossier — public-source company profileWest County Health Centers is a community health center providing comprehensive primary care and health services to residents of western Sonoma County, California. The organization operates with a mission emphasizing accessible, affordable, and equitable care across its service area.
- Industry
- Healthcare Services
- Address
- 14045 Mill Street, Guerneville, CA 95446, United States
- Employees
- 51-200
Attack summary
Severity: high — Healthcare sector victim with confirmed data exfiltration by ransomware operator; patient/medical data exposure at organizational scale poses regulatory and privacy risks under HIPAA and similar frameworks.Storm claims to have compromised West County Health Centers' systems and exfiltrated data. The group has published information about the victim but specific details regarding encrypted systems or the nature and scope of exfiltrated data are not detailed in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Patient records
- Healthcare data
- Organizational information
What the group claims
West County Health Centers provides comprehensive, quality and accessible health care services to the communities of western Sonoma County.The company is a cohesive team of health care providers, support staff and volunteers dedicated to wellness, compassion, affordability and excellence of care. The company believes in non-judgmental and equal care for all members of the company's diverse community. The company headquarters is located in 14045 Mill Street, Guerneville, CA 95446, United States. 51-200 Employees
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

