On July 19, 2026, City Ambulance Service was listed as a victim on the Qilin ransomware group's leak site, indicating a data breach. As of July 20, 2026, the company has not issued an official breach notification, statement, or letter.
The exposed data likely includes patient names, addresses, dates of birth, SSNs, medical treatment details, insurance information, and employee HR and payroll files. The exact number of affected individuals and specific states involved remain unconfirmed. Official breach notification letters and Attorney General filings have not yet been reported.
Ransomware groups often list victims before company confirmation. Official notifications typically follow weeks later after the victim assesses the scope. The exact data types, affected individuals, and states remain unconfirmed until City Ambulance Service releases an official statement.