Spirit Medical Transport, also known as Spirit EMS, experienced an alleged ransomware attack claimed by the Qilin group, with public reports emerging on May 13, 2026. This incident has not been officially confirmed by Spirit Medical Transport through a public statement or breach notification. Third-party reports from security researchers and law firms are the primary sources of information regarding this event.
The alleged breach may have compromised personal data and protected health information (PHI) of individuals in Western Ohio and Eastern Indiana. The types of data potentially exposed include names, addresses, dates of birth, Social Security Numbers, insurance information, medical history, treatment and transport records, emergency contact details, and billing/payment information. No specific number of affected individuals has been publicly disclosed or confirmed by Spirit Medical Transport.
As of the current information, Spirit Medical Transport has not issued an official public statement, notification letter, or filed with state Attorney Generals regarding this incident. No class action lawsuits have been confirmed, although some law firms are investigating the matter. Details about the full scope and impact of the breach may emerge over time as investigations progress and if official notifications are eventually made.