Attorneys are investigating Doctus, a healthcare services and technology solutions company, for a possible data breach reported in July 2026. This investigation follows a June 10, 2026, report by the Deadlock ransomware group claiming responsibility for an attack.
The potential breach may have exposed names, addresses, dates of birth, Social Security numbers (SSNs), insurance details, clinical notes, payment information, phone numbers, and internal files. Doctus acts as a third-party vendor for numerous medical practices nationwide, meaning patient data from multiple providers could be affected, though the exact number of individuals impacted remains unconfirmed.
Doctus has not yet issued a public statement or breach notification, and the incident has not been officially reported to HHS OCR or state Attorney Generals. Forensic analysis is pending to verify the extent of the data exposure.