McKenzie Memorial Hospital in Michigan disclosed a breach involving protected health information. More than 54k people were affected.
In the substitute notice on their website, they do not specify whether this was a ransomware attack, nor do they mention any extortion demand. What they do say, in part, is
"We have taken steps to address the incident and are committed to protecting the information entrusted to us. In response to this incident, we partnered with third-party specialists to conduct a full investigation and took action to mitigate the risk to the data. There is no indication that any information has been or will be fraudulently misused.”'
So... did they pay the unnamed attackers? Sounds to me like they did, but I wish they'd be clearer. I've emailed them to ask them directly.
And oh yes, as @amvinfe also reported, this was McKenzie's second #databreach with #PHI since early 2022.
https://databreaches.net/2025/07/28/two-data-breaches-in-three-years-mckenzie-health/