Capital Family Physicians, a family medicine practice in Raleigh, North Carolina that provides primary care services with an emphasis on pediatric care, has reported a data breach affecting 2,545 individuals to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR). HHS OCR investigates breaches of protected health information affecting 500 or more individuals under the HIPAA Breach Notification Rule.
Healthcare providers that maintain patient medical records and billing information are entrusted with some of the most sensitive personal data that exists, and they are required under federal law to notify both regulators and affected patients when that information is compromised.
Capital Family Physicians’s Data Breach Investigation
Capital Family Physicians reported to HHS OCR that a breach of protected health information affected 2,545 individuals in North Carolina. As a HIPAA-covered entity, the practice is required to notify HHS OCR of any breach affecting 500 or more individuals, and that report is what confirms the scope of this incident.
Separately, a ransomware group identifying itself as cmdorganization has publicly claimed responsibility for an attack on Capital Family Physicians, stating that it exfiltrated data from the practice and listing it on the group’s dark web leak site in late May 2026. Ransomware groups’ own claims about what they took and how much data was involved are not independently verified statements from the practice itself, and reported details about the incident, including the exact volume of data taken, have varied across different third-party sources tracking the group’s activity. For that reason, this article relies on Capital Family Physicians’s own regulatory filing with HHS OCR, which confirms the number of individuals affected, rather than on the unverified specifics claimed by the group behind the attack.
Capital Family Physicians has not publicly released a detailed breakdown of exactly which categories of protected health information were involved for the affected individuals, or the specific method by which unauthorized access to its systems occurred. Healthcare practices frequently maintain a broad range of sensitive information in a single electronic health record and billing system, including patient names, dates of birth, medical history, treatment information, and insurance and billing details, any combination of which can be exposed when a practice’s network is compromised.
Ransomware attacks against small and mid-sized medical practices have become increasingly common in recent years, in part because these practices often maintain valuable patient data without the same level of dedicated cybersecurity resources available to large hospital systems. When a ransomware group successfully accesses a practice’s systems, it typically both encrypts the practice’s own data to disrupt operations and separately copies, or exfiltrates, a portion of that data to use as additional leverage, threatening to publish it publicly if a ransom is not paid.
Patients whose protected health information is exposed in an incident like this one face risk beyond ordinary identity theft. Medical records and insurance information can be used to commit medical identity theft, in which a stolen identity is used to obtain healthcare services or prescription medications fraudulently, potentially resulting in inaccurate information being added to the victim’s own medical history.
Notification timelines for breaches involving ransomware groups that publish stolen data can differ significantly from breaches that are discovered and disclosed solely by the affected organization. When a ransomware group posts a claim on its own leak site, that public claim can become known to journalists, security researchers, and cybersecurity monitoring services well before the underlying organization completes its own internal investigation and files the required regulatory notifications. This gap can leave affected individuals reading about a potential breach in security news coverage before they receive any formal notice from the healthcare provider itself, which is one reason patients are encouraged to monitor their accounts proactively rather than waiting for a letter to arrive before taking protective steps.
When Did This Breach Occur?
A ransomware group calling itself cmdorganization listed Capital Family Physicians on its dark web leak site on or around May 29, 2026, claiming to have exfiltrated data from the practice. Capital Family Physicians’s own report to HHS OCR confirms that a breach of protected health information occurred, but the practice has not publicly disclosed the specific date the underlying unauthorized access began or when it was discovered internally.
What Information Was Breached?
Capital Family Physicians’s report to HHS OCR confirms that protected health information belonging to 2,545 individuals in North Carolina was affected. The practice has not publicly specified the exact categories of information involved for each affected individual. Given the nature of a family medicine practice’s records systems, potentially affected information could include patient names, medical records, treatment history, and billing or insurance information, though patients should rely on their own notification letter from Capital Family Physicians for confirmation of what specifically was involved in their case.
What You Can Do
- Watch for and carefully review any notification letter from Capital Family Physicians regarding this incident.
- Monitor your health insurance Explanation of Benefits statements for services you did not receive.
- Review your credit reports and financial account statements for unfamiliar activity.
- Consider placing a fraud alert or security freeze with the major credit bureaus.
- Report any suspected identity theft or medical fraud to the Federal Trade Commission at identitytheft.gov.
File a Data Breach Lawsuit Against Capital Family Physicians
If you received care from Capital Family Physicians and believe your information may have been affected by this breach, you may have legal options available to you. Healthcare providers are expected to maintain reasonable safeguards to protect the patient information in their care, and when a breach occurs, patients can be left facing the burden of monitoring their accounts and medical records for signs of misuse.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.