Mid-South Pulmonary & Sleep Specialists detected suspicious activity around November 2, 2025, which an investigation later confirmed to be unauthorized access to files. Ransomware group Anubis claimed responsibility for the patient data breach on November 28, 2025. The company posted a notice on its website on December 30, 2025, stating it was reviewing affected files to identify individuals and notify them.
The compromised data types include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical diagnoses. The specific number of affected individuals has not been publicly disclosed, as the company is still in the process of identifying them. The geographical scope of the breach is also unclear, although the company name suggests a regional US presence.
Details about the breach, including the total number of affected individuals and specific states involved, may still emerge. Official notifications to consumers were expected to follow the company's review process, which began in late 2025.