Heart of America Medical Center Data Breach Investigation

Written by 
Published on:
September 2, 2026
Updated on:
September 2, 2026

Heart of America Medical Center in Rugby, North Dakota has confirmed a data breach that exposed sensitive patient information, including Social Security numbers and medical records. The hospital serves patients across Rugby, Dunseith, and Maddock, ND.

The breach affects an unknown number of current and former patients. HAMC has not released a specific victim count, but the hospital reported the incident to the Massachusetts Office of Consumer Affairs and Business Regulation on August 5, 2026, a step required when a breach affects residents of that state.

How the Breach Happened

HAMC first noticed suspicious activity on its network around June 12, 2025. The hospital brought in a forensic team to look into it. By September 15, 2025, the investigation confirmed that an unauthorized party had gotten into the network and taken files. Some of those files contained patient information.

Around the same time, a ransomware group called Embargo claimed credit for the attack. On August 6, 2025, the group posted a notice on its dark web site claiming it had stolen 800 gigabytes of data from HAMC. It also posted sample screenshots as proof.

It took HAMC nearly a year to sort out exactly whose data was affected. A third-party vendor reviewed the stolen files, finishing that work on May 12, 2026.

The hospital then reviewed those findings and wrapped that up on June 9, 2026. After verifying contact information for everyone involved, HAMC finalized its list of people to notify on July 9, 2026. Notification letters started going out shortly after.

This kind of gap between discovery and notification is common in healthcare breaches. Sorting through hundreds of gigabytes of stolen data to figure out exactly whose information was taken takes time, and hospitals often bring in outside forensic firms to do it right.

What Information Was Exposed

According to HAMC's breach notice, the exposed data includes names, Social Security numbers, and medical records. Some reports also point to health insurance details among the stolen files. This is the kind of information that can be used for medical identity fraud and tax fraud.

A criminal using your Social Security number and medical history could file fraudulent insurance claims or get treatment under your name, and that can wreak havoc on your own medical records for years.

What HAMC Is Offering Affected Patients

HAMC is providing complimentary credit monitoring services to people affected by the breach. Details on enrollment are included in the notification letters sent to patients, and there's a deadline to sign up, generally around 90 days from the date on the letter. If you got a letter from HAMC, don't wait too long to enroll.

Credit monitoring can help you catch some kinds of fraud, but it won't catch everything. Medical identity theft in particular can slip past standard credit monitoring services, since it doesn't always show up as a new credit account.

What You Should Do Now

If you're a current or former patient of Heart of America Medical Center, watch your health insurance statements for treatments or services you never received. Consider placing a fraud alert or credit freeze with the major credit bureaus. And keep any notification letter you received from HAMC, since you may need it later.

Hospitals and medical centers are required under HIPAA and state data breach laws to protect patient information and to notify people when that information is compromised.

When a hospital fails to keep sensitive data secure, patients can sometimes hold the organization accountable through a lawsuit, and courts have allowed data breach victims to recover damages for things like the cost of credit monitoring and the ongoing risk of identity theft.

Talk to The Lyon Firm

If you received a notice about the Heart of America Medical Center data breach, or you believe your information may have been exposed, The Lyon Firm wants to hear from you. Our attorneys have handled data breach cases across the country and can help you understand whether you have a claim.

Reach out to The Lyon Firm today for a free, no-obligation case review. There's no cost unless we recover compensation for you.

Contact Us

Request a Free Consultation

Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there:

  • It begins with a few simple questions about your situation.
  • From there, a member of our legal team reviews your case.
  • Together, we’ll chart the path forward, helping you take the next step toward resolution.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.