Atrium Centers Data Security Incident

Written by 
Published on:
August 18, 2026
Updated on:
August 18, 2026

Atrium Centers, an employee-owned skilled nursing provider based in Columbus, Ohio, recently disclosed a data security incident that may have exposed sensitive personal and health information belonging to current and former patients and employees.

The company detected unusual activity on its network around October 13, 2025, and later determined that unauthorized actors had accessed its systems between October 8 and October 12. During that time, certain files and folders were allegedly viewed or copied without authorization.

What Information was Involved in the Atrium Centers Breach?

The information potentially involved in the incident includes names, contact information, dates of birth, Social Security numbers, driver’s license numbers, patient and medical record numbers, medical information, health insurance information, claim information, and, in some cases, financial account information.

The total number of people affected has not been publicly released. Given the types of information involved, affected individuals may face risks including identity theft and financial fraud.

In a notice on their website, Atrium Centers says it secured its systems after discovering the incident, began an investigation, notified law enforcement, and started reviewing the affected files to determine whose information was involved.

The company also issued a notice about the incident and established a dedicated assistance line for individuals with questions. The ransomware group Medusa later claimed responsibility for the attack on the dark web, although that claim should be distinguished from Atrium Centers’ own statements about the incident.

Next Steps Following a Data Breach

Anyone who received a notice about the breach should consider taking steps to protect their information. These may include reviewing bank and credit card statements for unfamiliar activity and obtaining free credit reports through AnnualCreditReport.com.

A fraud alert or credit freeze with the major credit reporting agencies can also make it more difficult for someone to open new accounts using stolen information. Anyone who discovers evidence of identity theft or other misuse should report it promptly to the appropriate authorities and the Federal Trade Commission.

Medical records and other health information can be particularly difficult to replace or change after a breach. Information such as Social Security numbers and medical histories may remain useful to criminals long after the initial intrusion. Individuals who believe their information was involved should keep copies of any breach notices and consider whether they may have legal claims related to the incident.

If you believe you were affected by the Atrium Centers data incident, contact our data privacy attorneys to discuss your rights and potential legal remedies. Acting promptly may help you understand what information was involved and what options may be available. Call now for a free consultation.

This post is for general informational purposes only and does not constitute legal advice. Atrium Centers has not admitted any wrongdoing in connection with this incident.

Contact Us

Request a Free Consultation

Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there:

  • It begins with a few simple questions about your situation.
  • From there, a member of our legal team reviews your case.
  • Together, we’ll chart the path forward, helping you take the next step toward resolution.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.