
Heart of America Medical Center, a nonprofit critical care hospital based in Rugby, North Dakota, disclosed a data breach that exposed sensitive personal, financial and medical information. The hospital has served the region since 1905, offering a wide range of services, including emergency care, surgery, rehabilitation, skilled nursing and assisted living.
The breach was disclosed to the Massachusetts Office of Consumer Affairs and Business Regulation on Aug. 5, 2026. The total number of individuals affected across the United States has not been publicly reported.
On or about June 12, 2025, Heart of America discovered suspicious activity on its network. An investigation into the scope of the incident revealed on Sept. 15, 2025, that files containing sensitive information belonging to individuals had been compromised.
On Aug. 6, 2025, a ransomware group known as Embargo posted a claim on its dark web portal. The group stated that it had obtained 800 gigabytes of data from Heart of America Medical Center and provided sample screenshots on its portal as apparent evidence of the data theft.
The types of personally identifiable information confirmed to have been exposed included medical records and Social Security numbers.
In addition, protected health information was exposed, including medical records and other medical information.
Heart of America is offering 24 months of complimentary access to credit monitoring services for affected individuals. To take advantage of these services, affecged individuals can follow the steps provided on its notification letters.
The deadline to enroll in the complimentary services is 90 days from the date listed on the notification letter.
Affected individuals should take protective steps as soon as possible to help reduce the risk of identity theft, financial fraud and medical identity fraud.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)