On January 4, 2026, Resource Corporation of America appeared on the Medusa ransomware group’s leak site with internal files the attackers claim to have exfiltrated during a ransomware incident. The company, based in Kemah, Texas, helps hospitals convert at-risk patient accounts into revenue through third-party eligibility services. While the exact number of individuals whose data may have been exposed remains unknown, anyone whose medical billing, insurance, or eligibility records passed through the firm in the past 30 years could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Resource Corporation of America
Get alerted the next time Resource Corporation of America files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Resource Corporation of America’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Medusa posted proof of compromise on its dark-web leak portal, listing Resource Corporation of America as victim number 20058b47f2b4df7a0402f1fc268880b9. The exposed material consists of internal files exfiltrated before encryption. No confirmed count of stolen records has been published, and the company has not yet issued a public statement detailing the breach scope or timeline. Available reporting describes the headquarters at 1120 Marina Bay Dr, Kemah, TX, and notes the firm’s long-standing role processing more than two billion dollars in patient account charges for hospitals nationwide.
Why This Matters for You and Your Family
When a healthcare revenue-cycle company loses control of internal files, the information inside often includes names, addresses, dates of birth, Social Security numbers, insurance details, and medical billing records. If your hospital used Resource Corporation of America to chase Medicaid, charity-care, or third-party payments, your family’s protected health information may now sit on a ransomware server. Medical data sells for far more than simple login credentials on the underground market and can be used to file fraudulent tax returns, open accounts in your name, or pressure you with threats of exposing sensitive diagnoses.
Even if you never directly hired the firm, the hospitals and clinics you trust likely did. That means one breach can ripple outward and put thousands of patient families at risk without any obvious warning.