Atrium Centers, a provider of skilled nursing care, discovered unusual activity on its IT systems on October 13, 2025. An investigation determined that unauthorized access to the network occurred between October 8, 2025, and October 12, 2025. During this period, files and folders were viewed or copied without authorization. A ransomware group named MEDUSA claimed responsibility for the attack and threatened to publish the stolen data. The breach was reported to the Vermont Attorney General on August 14, 2026. The potentially exposed data includes names, contact and demographic information, government identification numbers (such as Social Security and driver’s license numbers), patient identification numbers, medical record numbers, medical information, health insurance information, claim information, financial account information, and dates of birth. The total number of affected individuals has not been publicly disclosed. Atrium Centers operates primarily in Ohio, Michigan, Wisconsin, and Kentucky, and the breach was reported to the Vermont Attorney General. Details such as the exact number of affected individuals or the content of the official notification letter have not been fully surfaced in the available material. As with many data incidents, more information may become available over time, and affected individuals may receive notifications at later dates.