Claim details
Sinobi claimed 550 GB theft and sought a ransom. Heywood has not verified the group or amount.
Heywood Healthcare said a cybersecurity incident detected Oct. 12, 2025, disrupted networks at Heywood Hospital in Gardner and Athol Hospital in Athol, including communications and clinical systems, and led to ambulance diversions. Most services returned to the network and electronic health records by Oct. 31. A later breach notice confirmed unauthorized access to files containing patient information; Sinobi’s separate 550 GB theft claim was not verified by Heywood.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
Heywood Healthcare said a cybersecurity incident caused the outage affecting Heywood Hospital in Gardner and Athol Hospital in Athol. DysruptionHub reported that both hospitals took affected systems offline and engaged outside cybersecurity experts. Network and phone interruptions began Oct. 12–13, 2025. The initial technical access method and whether encryption occurred were not established.
Both hospitals continued inpatient care but used Code Black ambulance diversions after communications and other systems failed. Local and clinical reporting documented disrupted phones and provider contact; emergency medical services reported limited imaging capacity. Heywood said Oct. 31 that most services, including outpatient lab, radiology, clinics and inpatient units, were back on its network and electronic health records, while a small number of departments remained unrestored. Its official directory lists medical-group locations in Gardner, Athol, Ashburnham and Winchendon. The latter two are mapped as organization locations; reviewed sources do not confirm an individual outage at either clinic.
In a Dec. 10 Massachusetts-filed notice, Heywood said an unauthorized party accessed its network Oct. 12 and may have viewed or acquired files containing patients’ names, birth dates, procedure, medical record number, account number and diagnosis. A later New Hampshire filing describes a broader Oct. 8–12 access window, but the PDF could not be directly reviewed here; the dates warrant reconciliation. Separately, Comparitech reported that Sinobi claimed theft of 550 GB and demanded a ransom. Heywood did not verify Sinobi’s attribution or claimed volume. Official confirmation of unauthorized file access does not establish the group’s alleged amount or ransomware encryption.
Most operations were restored by Oct. 31, but no precise date for all departments was found. The incident is presumed resolved because no continuing service disruption was found after more than 30 days. The final scope of patient data, total affected people, relationship between the two breach notices, and attack method require further verification.
Sinobi claimed 550 GB theft and sought a ransom. Heywood has not verified the group or amount.




Heywood Healthcare operates Ashburnham Family Medicine here; no clinic-specific outage is established.
Hospital in athol documented as affected by network outage and ambulance diversion.
Hospital in gardner documented as affected by network outage and ambulance diversion.
Heywood Healthcare operates a Winchendon clinic here; no clinic-specific outage is established.
Heywood and Athol hospitals confirmed a cyber incident following network and phone disruption and ambulance diversions.
Heywood said the network outage was a cybersecurity incident, affected systems were taken offline, and outside experts were engaged.
Heywood Healthcare moved IT systems offline after the Oct. 12 incident; hospitals and medical group used downtime communication alternatives.
Local outlet reproduced the Heywood Oct. 31 statement that most clinical services had returned to network and EHR.
Most services, including lab, radiology, clinics and inpatient units, had returned to network and EHR; a few departments were not fully restored.
Sinobi alleged 550 GB theft. Heywood had not verified the group’s claims; Comparitech cited Oct. 31 recovery update.
Ransomware.live indexed a Sinobi leak-site claim naming heywood.org.
Heywood said unauthorized access Oct. 12 may have involved viewing or acquiring files containing names, birth dates, procedure, medical record, account and diagnosis information.
A later NH-filed notice describes Oct. 8–12 network access and acquisition of files containing personal information.
Official directory lists hospitals in Gardner and Athol and medical-group facilities in Gardner, Athol, Ashburnham and Winchendon.
Signed-in members can report an error, update, or missing source.