Skip to content

AdvancedHEALTH confirms data access after clinic ransomware outage

Summary

Advanced Diagnostic Imaging, P.C. logo

Advanced Diagnostic Imaging, P.C., doing business as AdvancedHEALTH, said it detected suspicious activity on April 28, 2026 and determined that an unauthorized actor gained access to information on its systems. Columbia Surgical Partners had separately described ransomware at its parent and loss of EHR access. AdvancedHEALTH’s June notice said its data review was ongoing and found no evidence of misuse; DragonForce’s claimed 390 GB theft remains unverified.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Healthcare operations disrupted

    Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Extortion indicators

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

Incident narrative

Analyst assessment

Advanced Diagnostic Imaging, P.C. (ADI), doing business as AdvancedHEALTH, has now made a firsthand disclosure. In a June 26 notice, ADI said it identified suspicious activity in its technical environment on April 28, secured the environment and investigated. The investigation determined that an unauthorized actor gained access to certain information on ADI computer systems. ADI said it was still conducting a comprehensive review to determine what information was present and to whom it related.

That disclosure strengthens the evidence for a confirmed cyber incident and confirms unauthorized access to information, but it does not itself identify ransomware. Ransomware remains supported by Columbia Surgical Partners’ earlier patient communication: the clinic said its parent had suffered a ransomware attack and that it could not access electronic medical records. DysruptionHub and WSMV documented that operational effect at the end of April.

Operational significance

The confirmed operational impact was loss of access to electronic medical records at Columbia Surgical Partners. EHR access supports review of patient histories, scheduling, surgical preparation, documentation and continuity of care. The inability to retrieve records therefore materially impaired normal clinical administration, although public reporting did not document canceled procedures, office closures or emergency-care effects.

Columbia Surgical Partners officially lists offices in Columbia, Pulaski and Lawrenceburg. Those are supported organization locations, but the public incident communication does not say whether all three offices used the unavailable EHR environment. Columbia remains the only high-confidence incident location; Pulaski and Lawrenceburg are not treated as confirmed or suspected impacted sites without office-specific evidence.

Victim disclosure and data findings

Columbia Surgical Partners provided the first known victim-side operational disclosure by telling patients about ransomware at its parent and inaccessible records. ADI’s June 26 notice later confirmed its own investigation and unauthorized access to information. ADI said it implemented additional technical safeguards and had no evidence of actual or attempted misuse as of the notice.

The notice does not identify the types of information involved, the number of affected people, when unauthorized access began or ended, whether data was copied from the environment, or whether notices were sent to specific individuals. It therefore supports the Unauthorized data access finding, not confirmed data theft, publication or the actor’s claimed patient-record totals.

DragonForce claim

Comparitech reported that DragonForce listed AdvancedHEALTH and claimed it stole approximately 390 GB of data, including 2.3 million lines of patient information, partner agreements, management files, payroll data and human-resources records. The group also threatened incremental publication. AdvancedHEALTH has not confirmed DragonForce, the claimed volume, those data categories, exfiltration or publication. Attribution therefore remains low confidence and separate from ADI’s confirmed unauthorized-access finding.

Organization identity

The Tennessee physician group’s current official website is ouradvancedhealth.com, which describes AdvancedHEALTH as a multi-specialty group with more than 550 providers across 40 specialties. This Tennessee organization is distinct from the Oregon health-plan organization using advancedhealth.com.

Current status

ADI’s June notice describes containment, investigation and added safeguards but does not provide an operational restoration date for Columbia Surgical Partners’ EHR. Because no continuing operational impact has been documented since May 1 and no positive all-clear is available, the incident remains assessed as presumed resolved rather than resolved. The data-content review was still underway on June 26.

Confidence and uncertainty

Confidence is high that malicious cyber activity affected ADI and disrupted EHR access at Columbia Surgical Partners. The clinic’s ransomware statement and ADI’s later unauthorized-access finding are consistent but do not establish that DragonForce conducted the intrusion.

Data unavailability and unauthorized data access are confirmed. Data theft, publication and specific exposed-data categories remain unconfirmed. ADI reported no evidence of misuse, which is not equivalent to proving that no data was copied or that no future misuse could occur.

Analytic gaps

The public record does not establish the initial access vector, malware deployment method, encryption scope, affected servers, backup impact, dwell time, ransom amount, payment status, negotiation history, unauthorized-access interval or final restoration date. It also does not establish an affected-person count, final data categories, impact across AdvancedHEALTH’s broader network, or operational effects at Columbia Surgical Partners’ Pulaski and Lawrenceburg offices.

Threat actor and claim

Listed as: AdvancedHealthSource: otherPublished: Discovered:

Claim details

DragonForce claimed AdvancedHEALTH and alleged theft of 390 GB including 2.3 million lines of patient data and corporate files. The victim did not confirm the claim.

Organizations involved

Impacted location

Sources

Tennessee clinic loses EHR access after ransomware

Columbia Surgical Partners said it could not access electronic medical records after a reported ransomware attack on its parent company, Advanced Diagnostic Imaging. The clinic provided no restoration timetable and the parent organization did not immediately comment.

Patient medical records compromised by cyberattack at Columbia surgical clinic

WSMV reported that Columbia Surgical Partners told patients its parent company had been hit by a ransomware attack and that the clinic was unable to access electronic medical records. The clinic said the issue was being addressed but gave no restoration timeline.

Cybercriminals say they breached AdvancedHealth, Tennessee clinic confirms

Comparitech reported that DragonForce claimed AdvancedHEALTH and alleged theft of 390 GB, including 2.3 million lines of patient data and corporate files. AdvancedHEALTH had not confirmed the actor’s allegations.

AdvancedHEALTH ransomware claim includes 2.3M patient rows

TechRepublic reported that DragonForce’s allegations remained unconfirmed while Columbia Surgical Partners’ EHR outage provided the clearest verified operational link to the parent-company incident.

Notice of Data Privacy Event

ADI said it detected suspicious activity on April 28, determined that an unauthorized actor gained access to certain information on its computer systems, secured the environment, investigated and added safeguards. Its information review was ongoing, and it reported no evidence of actual or attempted misuse.

AdvancedHEALTH

AdvancedHEALTH’s official Tennessee website describes the organization as an independent multi-specialty physician group with more than 550 providers across 40 specialties and hosts the June 26 privacy-event notice.

Columbia Surgical Partners

The practice’s official site lists offices at 1708 Alpine Drive in Columbia, 1119 East College Street in Pulaski and 726 North Locust Avenue in Lawrenceburg, Tennessee.

See something that needs correction?

Signed-in members can report an error, update, or missing source.