Data Breach & Privacy
Blog > Data Breach & Privacy
Interim HealthCare Data Breach: What Patients Need to Know
Interim HealthCare of Oklahoma City, a home health and hospice franchise, reported a hacking incident involving protected health information to federal regulators in July 2026, and two ransomware groups have since claimed attacks on Interim HealthCare entities. Here is what is confirmed, what is not, and what patients can do.

What Happened in the Interim HealthCare Data Breach
A hacking incident reported to federal regulators in July 2026
According to the U.S. Department of Health and Human Services Office for Civil Rights breach portal, Interim HealthCare of Oklahoma City, Inc. submitted a breach report on July 31, 2026. The portal categorizes the incident as a hacking/IT incident and lists the location of the breached information as email and a network server. Federal law requires HIPAA-covered entities to report breaches of unsecured protected health information affecting 500 or more individuals, and the report is listed among those currently under investigation.
Beyond the federal listing, the franchise has not published a public statement describing the incident, and a notification letter has not been located on the public breach lists maintained by the California, Vermont, or Massachusetts attorneys general as of this writing. When the incident occurred, when it was discovered, and how it happened have not been publicly detailed by the company.
What the Ransomware Groups Have Claimed
Two separate claims that Interim HealthCare has not confirmed
Reporting on the incident indicates that two ransomware groups have listed Interim HealthCare on their leak sites. According to HIPAA Journal, a group known as Genesis posted a claim on August 10, 2026, describing roughly a terabyte of data it said it took from Interim HealthCare operations in Oklahoma and Tulsa, including medical and patient records, and a second group known as Anubis posted a separate claim on August 21, 2026, describing roughly 530 gigabytes of largely business and franchisee records.
These are claims made by criminal groups, not statements by the company. HIPAA Journal reports that Interim HealthCare has not confirmed the validity of either claim, and it is not established whether the two listings reflect one intrusion or two, or how either relates to the incident the Oklahoma City franchise reported to federal regulators. Readers should treat the volumes and data descriptions in those postings as unverified.
What Information May Have Been Involved
Protected health information that has not been publicly itemized
Because the incident was reported to the Office for Civil Rights as a HIPAA breach, it is understood to involve protected health information. However, the specific categories of data, such as names, dates of birth, Social Security numbers, insurance details, or clinical information, have not been publicly itemized by the company as of the portal listing. Individual notification letters would typically describe the information involved for each person.
Home health and hospice records commonly combine identifying and insurance information with sensitive clinical details, so patients may wish to treat the situation with appropriate caution until more is known. Where health-related information may have been exposed, there can be an increased risk of medical identity theft, fraud, or targeted phishing, even where no misuse has been reported.
Who May Be Affected by the Interim HealthCare Breach
Oklahoma City franchise patients; other franchises report separately
Interim HealthCare describes itself as a national network of independently owned franchise locations providing home health, hospice, and staffing services, and each franchise is independently owned and operated. The July 2026 federal report was filed specifically by Interim HealthCare of Oklahoma City, Inc., so the individuals potentially affected are most likely current and former patients of that franchise, though the company has not published a breakdown.
The HHS portal currently lists 500 individuals, a figure that often reflects a preliminary or minimum reporting threshold rather than a final count, and no total has been published. Separately, a different franchise, Interim Healthcare of West Texas, reported an unrelated incident to the Texas Attorney General in April 2026 involving a third-party vendor; that incident is distinct from the Oklahoma City report. If you received a letter from Interim HealthCare of Oklahoma City referencing a data security incident, that notice may indicate your information was among the data reported to have been affected.
Steps You Can Take to Protect Yourself
Practical precautions while details remain limited
While the details of the Interim HealthCare incident are still emerging, affected patients may wish to consider a few precautionary steps:
- Watch for a notification letter. It may describe the specific information involved and any services being offered.
- Review your Explanation of Benefits statements. Watch for medical claims or services you did not receive, which can be a sign of medical identity theft.
- Check your credit reports. You are entitled to free annual credit reports at annualcreditreport.com, and you can watch for accounts or inquiries you do not recognize.
- Consider a fraud alert or credit freeze. These are available at no cost through Equifax, Experian, and TransUnion and can add a layer of protection.
- Stay alert to phishing. Be cautious of unexpected emails, calls, or texts referencing Interim HealthCare or the incident, and verify any outreach independently before responding.
This information is a general overview and is not legal advice; your situation may differ, and consulting a legal professional can help you understand rights that may apply to you.
Talk to Wilshire Law Firm
Were you affected by the Interim HealthCare data breach?
If your health information or personal data may have been involved in the Interim HealthCare data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.
Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.
FAQs
Interim HealthCare of Oklahoma City, Inc. submitted a breach report to the U.S. Department of Health and Human Services on July 31, 2026. The dates on which the unauthorized activity occurred or was discovered have not been publicly detailed by the company.
The HHS Office for Civil Rights portal categorizes the incident as a hacking/IT incident involving email and a network server. Two ransomware groups, Genesis and Anubis, have separately claimed attacks on Interim HealthCare, but the company has not confirmed either claim or publicly described how the incident occurred.
Because the incident was reported as a HIPAA breach, it is understood to involve protected health information, but the specific categories have not been publicly itemized by the company. Descriptions of the data in ransomware leak-site postings are unverified claims.
The HHS Office for Civil Rights portal lists 500 individuals, which often reflects a preliminary or minimum figure. Interim HealthCare of Oklahoma City has not published a total.
Interim HealthCare franchises are separately owned, and the July 2026 federal report was filed by the Oklahoma City franchise. A different franchise in West Texas reported a separate, unrelated incident earlier in 2026. Whether other franchises are affected by the incident described in the ransomware groups’ claims has not been established.
The company has not publicly announced whether complimentary credit monitoring or identity protection services are being offered. Any such services would typically be described in the individual notification letter, so it is worth reviewing any notice you receive.
Individuals who believe they were affected may have legal options, and data breaches involving protected health information can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts. A free case review with a legal professional can help you understand your potential rights.

