
A ransomware group known as Chaos claimed responsibility for a cyberattack on Central Ohio Primary Care Physicians, a physician owned medical group that serves more than 500,000 patients across central Ohio. According to cybersecurity researchers who tracked the incident, the attack is believed to have occurred on or around August 25, 2026.
Reports of the breach began circulating publicly the following day, when the group listed COPCP on a dark web leak site typically used to pressure victims into paying a ransom.
Contact an Ohio data breach attorney to learn more about your legal options and to discuss joining related class actions.
As of this writing, COPCP has not issued a public statement confirming the incident, and everything currently known comes from outside monitoring sources rather than the health system itself.
Reports vary somewhat on the scope of the alleged breach. Cybersecurity intelligence firm SOCRadar identified COPCP on the Chaos group's leak portal and noted that credentials connected to the organization's patient portal and internal network had surfaced in stealer log data collected in the weeks before the listing.
Separate reporting from cybersecurity monitoring outlets has estimated that somewhere between roughly 263 and 362 gigabytes of data may have been taken, though these figures have not been independently verified and should be treated with appropriate caution until COPCP or a qualified forensic investigator confirms the details.
Because COPCP is a healthcare provider, any confirmed exposure of patient information would likely involve data protected under HIPAA, including medical records or other personal identifiers used in day to day care. Employee data may also be at risk if internal systems were compromised, as some reporting suggests.
Given the sensitivity of the information healthcare organizations typically maintain, patients and staff who may be affected should stay alert for official breach notification letters and avoid sharing personal information in response to unsolicited calls or emails referencing this incident, since scammers often exploit public breach reports to conduct phishing schemes.
If you receive a notification letter or have concerns about how this situation may affect you, The Lyon Firm is available to answer questions and review your options at no cost. Contact our Ohio data privacy attorneys today for a free, confidential consultation.
Central Ohio Primary Care Physicians has not verified the reported breach, and the scope of data allegedly involved remain unsettled matters that may change as more information becomes available.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: