
A cybersecurity watchdog is reporting that MedEvolve, a healthcare technology and revenue cycle management company recently acquired by San Francisco based Emergence, may have been targeted by a ransomware group. Be aware that MedEvolve itself has not confirmed a breach, and the claim comes from threat intelligence monitoring, not from the company.
According to a report from SOCRadar, a dark web monitoring firm, MedEvolve was listed on September 3, 2026, on the leak site operated by a ransomware group known as Settra. Researchers say Settra has claimed dozens of other victims in recent months, mostly in the United States, and has previously targeted companies in technology, manufacturing and professional services alongside healthcare.
MedEvolve provides workflow automation and billing software used by physician groups, including practices in orthopedics, urology and ophthalmology. That client base is worth noting because if patient billing or scheduling data were ever involved, it could affect people well beyond MedEvolve's direct customers.
Healthcare data claims like this one tend to develop quickly. If MedEvolve or any affected client practice eventually confirms unauthorized access to patient information, individuals impacted may have legal options.
The Lyon Firm actively monitors emerging healthcare data breach reports, including unconfirmed claims like this one, and investigates potential litigation on behalf of affected patients once a breach is verified.
If you receive a notification letter referencing MedEvolve or a connected medical practice, contact our data breach lawyers for a free consultation to understand your rights.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: