Two healthcare providers were hit by ransomware groups within a short window, both involving substantial claimed data theft.
OVP Health was attacked by an emerging group calling itself Storm, which claimed responsibility and alleged theft of approximately 130 GB of sensitive data. The claimed contents include patient and employee records, medical documentation and financial data.
ProHealth Medical Group was hit by the Krybit group, which claimed to have stolen more than 114 GB of data.
As always with extortion group claims, the numbers come from the attackers and should be treated as unverified until the affected organisations confirm scope. Groups routinely inflate volume to increase pressure.
New names, established playbook
Storm and Krybit are both relatively recent entrants. August 2026 alone saw crews named Everest, Chaos and xpl0itrs claiming victims within the same few weeks. The constant turnover of brand names obscures a stable underlying reality: the ransomware-as-a-service model means new operations can launch with mature tooling, established leak site infrastructure and an experienced affiliate pool from day one.
For defenders, the practical implication is that tracking group names has limited defensive value. The techniques are shared across the ecosystem. Detection and response should be built around behaviours — credential abuse, lateral movement, backup deletion, mass encryption, bulk exfiltration — not around which brand claimed the victim.
Why healthcare remains the preferred target
The sector's exposure is structural:
- Care cannot pause. Diverting ambulances and cancelling procedures has immediate human cost, which creates immediate pressure to restore service by any means.
- Medical records are the richest available dataset. A single record can contain identity data, insurance details, financial information, diagnoses and family relationships — and unlike a card number, none of it can be cancelled.
- Medical devices resist patching. Regulatory certification means many connected devices run operating systems that cannot be updated without revalidation, and they sit on the same networks as everything else.
- Margins are thin. Security competes directly with clinical staffing and equipment in the budget process, and generally loses.
The consequences are measurable in clinical terms. Research has repeatedly linked ransomware disruption at hospitals to longer waits, delayed procedures and degraded outcomes — including at neighbouring facilities absorbing diverted patients.
What providers should prioritise
Recognising that budgets are constrained, the highest-value controls for healthcare organisations specifically:
- Segment clinical networks from corporate IT. If a phishing email in the finance department can reach an infusion pump VLAN, that is the finding that matters most.
- Inventory connected medical devices. You cannot protect what you have not counted, and most organisations undercount significantly.
- Immutable backups with tested clinical restore. Test restoring the electronic health record specifically, with clinical staff present, and time it.
- Practise downtime procedures. Paper-based clinical workflows exist in most hospitals as a binder nobody has opened. Run a drill.
- Phishing-resistant MFA for remote and administrative access. Remote access into clinical networks is the recurring initial access vector.
- Exfiltration detection. Double extortion means the data leaves before anything is encrypted. Alerting on large outbound transfers gives you the only early warning available.
The regulatory tail
Both incidents will carry notification obligations — HIPAA in the US, GDPR where EU residents' data is involved, and sector-specific rules elsewhere. Regulatory attention increasingly focuses less on whether an organisation was breached and more on whether reasonable safeguards were in place beforehand and whether notification was timely.
That shift is worth internalising. Documented risk assessments, evidence of control implementation and a rehearsed notification process are not paperwork exercises. They are the difference between an enforcement action and a closed file.


