Back to Exposure Report
Healthcare / Community HealthJuly 24, 2026United States

Cabin Creek Health Systems

A rural health center holds the same regulated record types as a hospital system, with a fraction of the people to inventory them — and some records the hospital does not hold at all.

Not yet disclosedFQHC records (inferred)Behavioral health data (inferred)Substance use treatment records (inferred)Medicaid identifiers (inferred)
1

What happened?

Cabin Creek Health Systems was listed as a victim on the INC Ransom leak site on July 24, 2026. Cabin Creek is a Federally Qualified Health Center operating clinics across rural West Virginia, providing primary care, behavioral health, dental services, and substance use treatment.

The listing has not been independently verified and the organization has not, as of this writing, issued a public confirmation. Leak site listings are claims, not confirmed breaches, and INC Ransom — like most extortion operations — has an incentive to overstate. What follows treats the listing as a claim and the sector context as the analysis.

2

What data was actually inside?

The specific data types have not been publicly disclosed as of this writing.

Based on the services a Federally Qualified Health Center delivers, the compromised environment would be expected to contain names, Social Security numbers, dates of birth, Medicaid and Medicare identifiers, sliding-scale income documentation, diagnoses, and behavioral health and substance use treatment records. This is a clearly labeled inference from the organization's service model, not a confirmed inventory.

One category carries weight the others do not. Substance use disorder treatment records held by a federally assisted program are protected under 42 CFR Part 2, a stricter regime than HIPAA, precisely because disclosure costs people custody, employment, and housing.

3

Who gets hurt and how?

FQHC patients are, by federal design, people who cannot readily get care elsewhere: uninsured and underinsured adults, Medicaid enrollees, and residents of medically underserved areas. Cabin Creek serves communities in a state at the center of the opioid epidemic.

If treatment records were exposed, the harm is not primarily financial. In a county of a few thousand people, a leaked patient roster is a document your neighbors, your employer, and your child's other parent can read. Substance use treatment disclosure has been used in custody proceedings and employment decisions. Sliding-scale income documentation, if present, additionally discloses poverty. The SSNs and Medicaid IDs support the ordinary identity and medical fraud on top of that — but for this population the disclosure itself is the injury.

4

What did they think they were doing right?

While not publicly confirmed, community health centers of this type typically operate under HRSA oversight with documented HIPAA compliance programs, security risk assessments, and — for Part 2 records — additional consent and segregation requirements. Compliance obligations are met because grant funding depends on meeting them.

That is the trap. A HIPAA security risk assessment is a periodic document produced for a regulator. It confirms that policies exist and that a review occurred. It does not produce a live map of where protected health information has actually accumulated across the EHR, the practice management system, the dental module, the behavioral health tooling, and the reporting extracts a grant application required in 2021.

5

What did they not know about their own data?

42 CFR Part 2 requires substance use treatment records to be handled more restrictively than the rest of a patient's chart. In practice, that separation is often maintained at the application layer — the behavioral health module enforces access controls — while the underlying data flows into shared reporting databases, backups, and analytics extracts where the distinction disappears.

An organization can be fully compliant at the point of care and still be unable to answer the question an incident poses: which of the files in the compromised environment contain Part 2 records? That question has to be answerable before the breach, because the answer determines the legal regime, the notification content, and the harm assessment.

Community health centers run on grant cycles. Security competes directly with clinical staffing. The data does not scale down to match the budget.

If you handle patient data, could you identify within 24 hours exactly which records were accessed in a breach?

6

What does attribution look like the morning after?

If protected health information was involved, the HIPAA Breach Notification Rule requires notification without unreasonable delay and no later than 60 days from discovery, with breaches affecting 500 or more individuals reported to the HHS Office for Civil Rights and posted on the OCR breach portal. West Virginia's state breach statute applies in parallel.

The operational reality for an organization this size is that there is no internal team to do it. Document review, legal analysis, notification drafting, and credit monitoring procurement all get contracted out, against an unbudgeted expense in an organization funded by grant. Meanwhile the clinics have to keep seeing patients. The ransom demand is rarely the number that matters; for a small FQHC, the response cost alone can exceed a meaningful share of annual operating margin.

7

What would have changed the outcome?

Knowing which systems hold Part 2 records and which hold ordinary PHI — before an incident forces the distinction to be reconstructed under a 60-day clock.

Small providers cannot buy their way to enterprise security, and pretending otherwise is not useful advice. What they can do is know where the most legally protected records live, so that limited protection goes to the right systems and, if the worst happens, the notification can be accurate and fast. The organizations that come through this best are not the ones with the largest security budget. They are the ones who could already name every place a treatment record had been copied to. See also our analysis of the Clinton Health Access Initiative listing, where sensitive health data sits almost entirely outside notification law.

Cabin Creek Health Systems found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.