Skip to content

Pit River Health Service cyber incident

Summary

Pit River Health Service logo

Pit River Health Service reported a cybersecurity incident that interrupted electronic health record and Dentrix dental-system access in December 2025. Patients were asked to bring medication and insurance information while staff used slower paper-based processes; the clinic later said some information may have been copied.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Pit River Health Service experienced a cybersecurity incident that materially disrupted care administration in December 2025. Our Dec. 17 report described the clinic’s Dec. 1 and Dec. 17 patient notices. The first said electronic health records and Dentrix were unavailable. The later notice said some systems had been restored and raised concern that information may have been copied. The record does not establish ransomware or an actor.

Operational significance

The system outage forced slower paper-based processes while appointments continued. Patients were asked to bring current medication lists and insurance cards. The reviewed report does not establish canceled appointments or an outage of the separate Indian Health Service medical record system.

Current status

The clinic’s Jan. 22 update said some systems were fully online while others remained under security review. It also said possible copying was under investigation and that a breach notification had been filed with HHS OCR. No reviewed source establishes a final restoration date. With no later operational disruption documented in the reviewed material, this retrospective record is presumed resolved without treating that as a confirmed all-clear.

Confidence and uncertainty

The victim’s own notices support high confidence in a cyber incident and material EHR and dental-software disruption, while possible information copying remains under investigation. The type of information and number of affected people were unresolved in the December notices; no reviewed primary record supports a final exposure count here.

Analytic gaps

The initial intrusion date, attack mechanism, affected data categories, threat actor and final restoration date remain unresolved.

Organizations involved

Impacted locations

  • Alturas, California

    Medium Confidence

    Alturas is a clinic location of the affected health service. The published incident evidence does not establish a separate outage at this clinic.

  • Burney, California

    Burney is the headquarters and clinic site named in the report; the record does not establish separate Alturas site effects.

Sources

Pit River Health Service cyber incident disrupts records access in California

We reported that Pit River Health Service’s December patient notices described unavailable electronic health records and Dentrix, paper workarounds, partial restoration by Dec. 17 and information copied or taken.

Update on Status of Pit River Health Service Cybersecurity Incident

In its Jan. 22 patient letter, Pit River Health Service said some systems were back online, others remained under security review, some information may have been copied, and the Indian Health Service medical record system was not accessed. It said it filed a breach notification with HHS OCR while assessing individual notices.

See something that needs correction?

Signed-in members can report an error, update, or missing source.