On February 1, 2025, the ransomware group known as threeam added sehma.com to its public leak site, claiming that it had exfiltrated internal files from SEHMA, a home health care provider network that delivers nursing, infusion, durable medical equipment, and diagnostic services to patients across multiple locations.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch sehma.com
Get alerted the next time sehma.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about sehma.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Public reporting indicates the incident began as a ransomware attack in which threeam gained access to SEHMA’s internal systems, copied sensitive files, and later listed the victim on its dark-web leak page. The exact number of individuals affected remains unknown, but the data includes internal documents that would typically contain protected health information, employee records, vendor contracts, and operational details. No specific deadline for ransom payment has been publicly disclosed in available reporting, though ransomware groups routinely set short windows before releasing more data.
The listing appears on the group’s dedicated leak site, hosted on an onion domain, and was first indexed by ransomware tracking services such as ransomware.live. SEHMA has not yet issued a public statement confirming the breach or detailing the precise scope of exposed records.
Why This Matters for You and Your Family
When a health-care provider’s internal files are stolen, the information often includes names, addresses, dates of birth, Social Security numbers, medical histories, insurance details, and sometimes family member contacts. If you or anyone in your household has received care from SEHMA or one of its affiliated companies, your personal health and financial data may now sit in the hands of criminals. That information can be sold, used for identity theft, or combined with other leaks to build a complete profile of your family.