Pit River Health Service

Pit River Health Service reported a cybersecurity incident that interrupted electronic health record and Dentrix dental-system access in December 2025. Patients were asked to bring medication and insurance information while staff used slower paper-based processes; the clinic later said some information may have been copied.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
DysruptionHub assesses with high confidence that Pit River Health Service experienced a cybersecurity incident that materially disrupted care administration in December 2025. Our Dec. 17 report described the clinic’s Dec. 1 and Dec. 17 patient notices. The first said electronic health records and Dentrix were unavailable. The later notice said some systems had been restored and raised concern that information may have been copied. The record does not establish ransomware or an actor.
The system outage forced slower paper-based processes while appointments continued. Patients were asked to bring current medication lists and insurance cards. The reviewed report does not establish canceled appointments or an outage of the separate Indian Health Service medical record system.
The clinic’s Jan. 22 update said some systems were fully online while others remained under security review. It also said possible copying was under investigation and that a breach notification had been filed with HHS OCR. No reviewed source establishes a final restoration date. With no later operational disruption documented in the reviewed material, this retrospective record is presumed resolved without treating that as a confirmed all-clear.
The victim’s own notices support high confidence in a cyber incident and material EHR and dental-software disruption, while possible information copying remains under investigation. The type of information and number of affected people were unresolved in the December notices; no reviewed primary record supports a final exposure count here.
The initial intrusion date, attack mechanism, affected data categories, threat actor and final restoration date remain unresolved.

Alturas is a clinic location of the affected health service. The published incident evidence does not establish a separate outage at this clinic.
Burney is the headquarters and clinic site named in the report; the record does not establish separate Alturas site effects.
We reported that Pit River Health Service’s December patient notices described unavailable electronic health records and Dentrix, paper workarounds, partial restoration by Dec. 17 and information copied or taken.
In its Jan. 22 patient letter, Pit River Health Service said some systems were back online, others remained under security review, some information may have been copied, and the Indian Health Service medical record system was not accessed. It said it filed a breach notification with HHS OCR while assessing individual notices.
Signed-in members can report an error, update, or missing source.