
A ransomware group called DireWolf claims it stole data from Hazel Health, a California-based school telehealth provider. The breach monitoring service Breachsense recorded the claim on September 15, 2026. Hazel Health has not publicly confirmed a breach, and the allegations remain unverified.
Breachsense lists the claimed leak at 341 gigabytes. Hazel Health connects K-12 students with virtual physical and mental health care. The public listing does not say what types of information the files contain or how the group obtained them. Tracker RansomLook describes DireWolf as a double-extortion group that first appeared in May 2025, meaning it threatens to publish stolen files to pressure victims.
A leak-site listing is a claim by the group behind it. It does not verify what happened, what data was taken, or who was affected. Until Hazel Health, a school district, or a regulator provides details, families should treat the reports as unconfirmed.
California law gives residents rights when organizations fail to protect personal or medical information. Whether a claim exists depends on what data was taken and what security measures the company maintained. Those facts take technical and legal work to establish.
The Lyon Firm represents plaintiffs in healthcare data privacy cases nationwide. If you or your child used Hazel Health services, our attorneys can explain your options. Call (513) 381-2333, or contact The Lyon Firm online for a free, confidential consultation.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: