Sandhills Medical Foundation
bd_e8ad9aefe6d9ba87 · schema v1 · pii pii-v1
Full breach record for Sandhills Medical Foundation →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group INC Ransom on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Sandhills Medical Foundation, Inc. is a Federally qualified community health center (FQHC) that has been providing comprehensive healthcare services since 1977. With locations in Chesterfield, Kershaw, Lancaster, and Sumter Counties, the organization focuses on primary care medicine, mental health, and supportive services such as healthcare navigation for Medicaid and the Affordable Care Act. The foundation aims to address community healthcare needs by delivering quality and cost-effective services to its patients. It also emphasizes preventive care and coordination of care through a patient-centered medical home approach
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jun 3, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Indiana State AGbd_14fe8ca7b959b0672026-04-28 · +329dVerified by operator
- South Carolina State AGbd_838e2f76c0067c242026-04-28 · +329dVerified by operator
- Indiana State AGbd_96138f16bf8d0e582026-04-28 · +329dVerified by operator
- Maine State AGbd_af253afef01a24142026-04-28 · +329dVerified
Show 6 more filings ↓Show fewer ↑up to 365d gap
- New Hampshire State AGbd_dd63827fbf969c242026-04-29 · +330dVerified by operator
- Vermont State AGbd_fb38a941440b89702026-04-29 · +330dVerified by operator
- Nebraska State AGbd_9ca75cbc5dd187072026-06-02 · +364dVerified by operator
- Texas State AGbd_b626cd7670911b3a2026-06-02 · +364dVerified by operator
- New Hampshire State AGbd_cf1144d9d57c47492026-06-02 · +364dVerified by operator
- Maine State AGbd_b0d44c29b558587c2026-06-03 · +365dVerified by operator
Showing first 10 of 13 linked disclosures.
Filing propagation · 11 filings · 7 states
View merged incident ↗Pattern: first filing Jun 3, last Jun 3 (ME) — a 365-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 13 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.