Ransomware.live listed PayrHealth as a victim on 2026-08-15 and tagged the incident to the Direwolf group. The listing described the target as healthcare, but no source in the record provided a public company statement, regulator notice, or breach notification. No affected-count figure, data-type list, state list, or notice timeline was available in the source record. The available material did not confirm whether Social Security numbers, medical information, or financial information were exposed. Details in incident listings can change as notices or filings appear later, and some items may remain unconfirmed until the company or a regulator publishes them.