Central Ohio Primary Care Physicians Data Breach Investigation

Written by 
Published on:
August 29, 2026
Updated on:
August 29, 2026

A ransomware group known as Chaos claimed responsibility for a cyberattack on Central Ohio Primary Care Physicians, a physician owned medical group that serves more than 500,000 patients across central Ohio. According to cybersecurity researchers who tracked the incident, the attack is believed to have occurred on or around August 25, 2026.

Reports of the breach began circulating publicly the following day, when the group listed COPCP on a dark web leak site typically used to pressure victims into paying a ransom.

Contact an Ohio data breach attorney to learn more about your legal options and to discuss joining related class actions.

What Happened at COPCP?

As of this writing, COPCP has not issued a public statement confirming the incident, and everything currently known comes from outside monitoring sources rather than the health system itself.

Reports vary somewhat on the scope of the alleged breach. Cybersecurity intelligence firm SOCRadar identified COPCP on the Chaos group's leak portal and noted that credentials connected to the organization's patient portal and internal network had surfaced in stealer log data collected in the weeks before the listing.

Separate reporting from cybersecurity monitoring outlets has estimated that somewhere between roughly 263 and 362 gigabytes of data may have been taken, though these figures have not been independently verified and should be treated with appropriate caution until COPCP or a qualified forensic investigator confirms the details.

What Central Ohio Primary Care Data Was Exposed?

Because COPCP is a healthcare provider, any confirmed exposure of patient information would likely involve data protected under HIPAA, including medical records or other personal identifiers used in day to day care. Employee data may also be at risk if internal systems were compromised, as some reporting suggests.

Given the sensitivity of the information healthcare organizations typically maintain, patients and staff who may be affected should stay alert for official breach notification letters and avoid sharing personal information in response to unsolicited calls or emails referencing this incident, since scammers often exploit public breach reports to conduct phishing schemes.

If you receive a notification letter or have concerns about how this situation may affect you, The Lyon Firm is available to answer questions and review your options at no cost. Contact our Ohio data privacy attorneys today for a free, confidential consultation.

Central Ohio Primary Care Physicians has not verified the reported breach, and the scope of data allegedly involved remain unsettled matters that may change as more information becomes available.

Contact Us

Request a Free Consultation

Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there:

  • It begins with a few simple questions about your situation.
  • From there, a member of our legal team reviews your case.
  • Together, we’ll chart the path forward, helping you take the next step toward resolution.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.