On February 5, 2025, Rural Health Services, a Federally Qualified Health Center serving Aiken County and surrounding areas in South Carolina, appeared on the leak site of the Medusa ransomware group. The nonprofit organization, which has provided primary and preventive healthcare since 1971, is claimed to have had internal files exfiltrated during a ransomware attack. Public reporting indicates that the number of affected individuals remains unknown at this time.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details of the Incident
The Medusa group posted proof of the breach on its dark-web leak site, listing Rural Health Services as a victim. Available reporting describes the exposed material as internal files that were allegedly stolen before encryption occurred. The organization operates from its corporate office at 120 Darlington Drive in Aiken, South Carolina, and employs approximately 100 staff members. No specific patient data types or volume have been publicly detailed in the initial listing.
Why This Matters for You and Your Family
When a local health center is hit, the people who rely on it for routine care, prescriptions, and children’s check-ups can find their personal information at risk. Medical records often contain dates of birth, Social Security numbers, addresses, and insurance details that criminals can use for identity theft or fraud. Even if you are not a current patient, family members who have visited over the years could be exposed. A single breach like this can quietly sit in criminal circles for months before the consequences reach your mailbox or credit report.
The Doxxing and Identity-Chain Risks
Stolen internal files frequently include employee directories, vendor contacts, and patient correspondence that link names to email addresses, phone numbers, and sometimes family relationships. Attackers chain these fragments with data from earlier breaches to build complete profiles. A leaked work email can lead to a personal account, then to a child’s gaming username that shares the same password or recovery phone. Once the chain exists, doxxing escalates quickly from identity theft to harassment or targeted scams. Credential leaks like this one cascade into account takeovers that affect both adult and children’s online lives.