Back to Exposure Report
Healthcare / Specialty PracticeAugust 2026United States

The Heart Center of Memphis

A cardiology practice — the kind of organisation that has an office manager, not a security team, and a data footprint that does not scale down to match.

Not yet disclosedCardiac diagnoses and medications (inferred)Implanted device telemetry (inferred)Imaging and test results (inferred)
1

What happened?

The Heart Center of Memphis was listed by LockBit on August 27, 2026. The listing has not been independently verified, the practice has not publicly confirmed an incident, and no data types have been disclosed as of this writing.

Specialty medical practices are among the most frequent victims in this series and among the least covered elsewhere.

2

What data was actually inside?

Not disclosed. What a cardiology practice holds, labeled as inference from clinical workflow: patient demographics, insurance and billing records, cardiac diagnoses, medication regimens, stress test and echocardiogram results, catheterisation reports, and implanted device data.

Cardiology records are unusually predictive. A cardiac diagnosis with a medication regimen and test results describes not just a condition but a prognosis — information that insurers, employers, and litigants have concrete uses for.

3

Who gets hurt and how?

Cardiac patients, a population that skews older and is therefore disproportionately targeted by fraud and least likely to be actively monitoring credit files.

The clinical disclosure is permanent. A record establishing heart failure, arrhythmia, or a cardiac event cannot be reissued, and it has bearing on employment, insurance underwriting in some contexts, and litigation. The billing data supports the usual medical identity theft, where fraudulent claims attach to a real benefit record.

Device telemetry deserves separate mention. Pacemakers and implantable defibrillators generate continuous remote monitoring streams — a named individual's cardiac activity over time, which is both medically revealing and, in aggregate, a record of where and when they were.

4

What did they think they were doing right?

While not publicly confirmed for this practice, specialty practices generally maintain HIPAA compliance programmes with documented security risk assessments, because the assessment is required and audited. Most contract IT support from a local provider or a healthcare-specific managed service.

A HIPAA security risk assessment is a periodic document produced for a regulator. It confirms policies exist and a review occurred. It does not produce a live map of where protected health information has accumulated — the EHR, the practice management system, the imaging archive, the device manufacturer's monitoring portal, and the referral correspondence sitting in a shared mailbox.

5

What did they not know about their own data?

Device telemetry is the clearest example of data that arrives outside the systems anyone inventoried. Remote monitoring for implanted cardiac devices flows through the manufacturer's portal rather than the EHR, and clinical staff access it through a separate login that was set up once and never reviewed.

Very few practices have ever established where that telemetry is stored, how much of it is retained locally, or which staff accounts can reach it. It is patient data by any definition and it lives in a place the practice does not think of as one of its systems.

The broader pattern holds across specialty medicine: the record does not scale down to match the organisation. A practice with a dozen staff carries the same regulated data categories as a hospital system, with none of the capacity to map them.

If you handle patient data, could you identify within 24 hours exactly which records were accessed in a breach?

6

What does attribution look like the morning after?

HIPAA applies in full and does not scale with organisation size. The 60-day notification deadline, reporting to the HHS Office for Civil Rights, publication on the OCR breach portal for breaches of 500 or more individuals, and Tennessee's state statute all apply exactly as they would to a hospital system.

The practice has no capacity to run any of it. Forensics, legal analysis, notification drafting, mailing, and credit monitoring are all contracted at unbudgeted expense while the clinics keep seeing patients. For a practice of this size, response costs alone can exceed a meaningful share of annual margin — and the ransom, if one is demanded, is rarely the largest number involved.

7

What would have changed the outcome?

A list of every system holding patient data — including the vendor portals nobody thinks of as systems — maintained by someone at the practice.

Small practices cannot buy enterprise security, and advice that assumes otherwise is not useful. What is achievable is knowing what you have and where it is: the EHR, the imaging archive, the device manufacturer's portal, the shared mailbox holding referral correspondence. That inventory costs staff hours rather than licences, and it converts a months-long scoping exercise into a days-long one. Ask who at your practice could produce that list today. See also our analysis of Cabin Creek Health Systems and Radiology Associates of Richmond.

The Heart Center of Memphis found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.