On June 3, 2026, Family Medical Associates of Raleigh appeared on the leak site of the Genesis ransomware group in a listing claiming internal files were exfiltrated during a ransomware attack on the North Carolina healthcare provider.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates the organization’s data was posted to the Genesis leak site hosted on the dark web. The files consist of internal documents taken during the intrusion. No confirmed total of affected individuals has been released, and the precise volume or specific categories of patient information remain unclear from available reporting. The listing carries a typical ransomware deadline for negotiation or further publication. Industry research from sources such as DoxxScan™ continuous monitoring has not yet catalogued this incident, which is common when data first surfaces on ransomware leak sites.
Why This Matters for You and Your Family
When a local medical practice is hit, the people most at risk are the patients whose addresses, dates of birth, Social Security numbers, insurance details, and treatment records may now sit in an attacker’s archive. Healthcare data is especially damaging because it combines financial identifiers with sensitive medical history that can be used for identity theft, insurance fraud, or blackmail. If you or your family have ever visited Family Medical Associates of Raleigh, your information could already be in circulation. Even without a confirmed patient count, the exposure of internal files means anyone connected to the practice should treat their data as compromised until proven otherwise.
The Doxxing and Identity-Chain Risks
Stolen medical records rarely stay isolated. Attackers routinely cross-reference exposed emails, phone numbers, and addresses with credentials from earlier breaches. This creates an identity chain that can link your doctor’s records to your online accounts, social-media handles, and even your children’s gaming profiles. Once the chain is built, opportunistic criminals can move from identity theft to account takeovers and full doxxing. Credential leaks like this one frequently cascade into gaming account compromises because the same email and password combinations are reused across services. Protecting both adult and children’s accounts is therefore essential.