On Demand Occupational Medicine, a workforce health provider based in Austintown, Ohio that offers occupational health, drug testing, workplace safety, and employee wellness services, may have suffered a data breach after a ransomware group claimed responsibility for an attack on the company. Companies entrusted with sensitive employee and patient health information have a responsibility to keep that data secure, and attorneys are now investigating whether On Demand Occupational Medicine met that obligation.
On Demand Occupational Medicine’s Data Breach Investigation
Attorneys working on behalf of individuals connected to On Demand Occupational Medicine are investigating whether the company failed to adequately protect personal information after a ransomware group calling itself Wallstreet listed the company on its dark web leak site. According to public reporting, the disclosure was posted on September 10, 2026, and the estimated date of the attack was the same day, though the true date of initial compromise in incidents like this frequently predates the date a group actually posts about it publicly. On Demand Occupational Medicine has not yet publicly confirmed the incident or issued a formal notification describing what information, if any, was accessed or acquired.
Ransomware attacks against healthcare and occupational health providers have become increasingly common because these organizations store large volumes of highly sensitive information, including Social Security numbers, medical histories, and insurance details, while often relying on smaller IT security budgets than hospital systems or large insurers. That combination makes healthcare-adjacent businesses an attractive target for a double-extortion model, in which an attacker both encrypts a victim’s internal systems and threatens to publish stolen files unless a ransom is paid. Even when a company declines to pay, the mere threat of publication can put affected individuals at heightened risk long before any official notification goes out.
Notification timelines in incidents like this one are governed by a patchwork of state data breach laws, most of which require a company to notify affected individuals within a set window, often 30 to 60 days, once it determines that personal information was actually accessed or acquired without authorization. That determination itself can take weeks, since a forensic investigator typically has to confirm which systems were touched, whether data was exfiltrated as opposed to merely encrypted, and which specific records or file types were involved before a company can responsibly describe the scope of an incident to the public or to regulators. It is not unusual for the initial leak site posting, as happened here, to arrive well before any of that forensic work has concluded, which is why early public reporting on a ransomware claim often lacks the specifics that a later formal notification letter eventually provides.
Because On Demand Occupational Medicine provides services to other companies’ workforces, including coordination with affiliated providers, any confirmed breach could extend well beyond the company’s own direct patients to the employees of the businesses it serves. Investigations like this one typically take time to develop a full picture, since state and federal notification laws generally give a company a window of weeks to months after discovering unauthorized access before it must formally notify affected individuals and regulators, and the scope of what was taken is often not finalized until a forensic review is complete.
In the meantime, individuals connected to the company, whether as employees, clients, or workers referred for occupational testing, are encouraged to stay alert for any breach notification letter mailed to them and to watch for signs their information has been misused. Data commonly targeted in this type of incident, such as Social Security numbers and dates of birth, can be used for years after a single exposure to open fraudulent accounts, file false tax returns, or attempt medical identity theft, which is part of why attorneys move quickly to investigate reported incidents even before a company’s own notification process concludes.
Ransomware disclosures that surface first on a hacker’s own leak site, rather than through a company’s own press release or a filing with a state attorney general, tend to move faster in the public eye than the legal process that follows them. Attorneys often begin reviewing the public reporting on an incident like this well before an affected company issues any formal notice, so they can be ready to act on behalf of anyone who later receives a letter confirming their information was involved. If you have not yet received any communication from On Demand Occupational Medicine but are concerned about this reported incident, it is still worth reaching out, since eligibility for a potential claim is generally tied to whether your information was actually exposed, not to whether you have already been formally notified.
When Did This Breach Occur?
The incident became public on September 10, 2026, when the Wallstreet ransomware group listed On Demand Occupational Medicine on its dark web leak site, with the estimated attack date also reported as September 10, 2026. On Demand Occupational Medicine has not yet issued its own public statement confirming the incident or specifying when any unauthorized access to its systems may have actually begun, which is common in the early stages of a ransomware-related disclosure before a company’s forensic investigation is complete.
What Information Was Breached?
As of this writing, the specific categories of information involved in the alleged On Demand Occupational Medicine breach have not been publicly disclosed. Attorneys investigating the incident note that the type of information typically at risk in a healthcare or occupational health data breach includes names, Social Security numbers, dates of birth, medical and treatment records, and insurance information, but no confirmed list of impacted data types tied to this specific incident has been released. This page will be updated if and when a formal notification or additional public disclosure clarifies exactly what information was affected.
What You Can Do
If you believe you may have been affected by the alleged On Demand Occupational Medicine data breach, consider the following steps:
- Watch your mail for any official breach notification letter from On Demand Occupational Medicine or an affiliated company.
- Monitor your bank and credit card statements closely for unfamiliar charges.
- Check your credit reports for accounts you don’t recognize, and consider placing a fraud alert or credit freeze with the major credit bureaus.
- Be cautious of unexpected calls, texts, or emails referencing this incident, since scammers sometimes use news of a breach to run phishing schemes.
- Keep any notification letter or documentation you receive, as it may be relevant if you decide to pursue legal action.
File a Data Breach Lawsuit Against On Demand Occupational Medicine
If you were affected by the alleged On Demand Occupational Medicine data breach, you may be entitled to compensation for losses tied to the exposure of your personal information, including time spent monitoring your accounts, out-of-pocket costs, and other resulting harm.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.