Praxis EMR, a California-based healthcare software and electronic medical records company, has been named by a hacker group that claims it carried out an attack. The company has not publicly confirmed a breach, and the claim was posted on October 5, 2026.
Praxis EMR’s Data Breach Investigation
Praxis EMR is a California-based company that provides healthcare software and electronic medical records tools to medical practices. Software of this kind sits at the center of a clinic’s daily work, holding patient charts, contact details, insurance information, appointment histories and clinical notes. That concentration of sensitive data is exactly what makes health technology vendors a steady target for extortion-style cyberattacks.
On October 5, 2026, the dark web monitoring site Ransomware.live listed Praxis EMR as a victim of a hacker group calling itself Insomnia, and estimated that the attack took place on September 17, 2026. A second cybersecurity monitoring platform, Breachsense, similarly reported that Insomnia claimed responsibility for an attack on Praxis EMR. Neither listing, as reviewed for this page, described how much data was involved or what kinds of files the group says it holds.
It is important to be clear about what is and is not known. Everything above comes from the attackers’ own posting and from sites that track those postings. Praxis EMR has not, as of this writing, publicly confirmed that an incident took place, has not described how any intruder got in, and has not said how many people may be affected. No state attorney general filing or notice letter has been located. Claims made by hacker groups are not always accurate, so this page treats them as unverified allegations rather than established fact.
Groups of this kind typically work by breaking into a network, copying files, and then threatening to publish the stolen data on a leak site unless a payment is made. Posting a victim’s name is usually the first public step in that pressure campaign, and any stolen files may be released later if no deal is reached.
Because Praxis EMR is a technology vendor rather than a clinic, an incident at the company could reach well beyond its own employees. Software and records providers generally hold information on behalf of their healthcare customers, which means the people whose data is involved may be the patients and staff of those customers, many of whom have never heard of the vendor. If a claim like this turns out to be true, the affected individuals may learn about it through a letter from their own doctor’s office or from the vendor.
The potential consequences can be serious if electronic medical records are exposed. Records of this kind can contain names, addresses, dates of birth, insurance details, diagnoses, treatments and medications. Any of these can be used to build a convincing phishing message, to commit insurance or medical identity fraud, or to pressure someone with sensitive information. Medical details also cannot be changed the way a password or a credit card number can, which is one reason health data is valued so highly by criminals.
When a healthcare vendor confirms that patient information was accessed without permission, federal and state breach notification rules generally require notice to the healthcare providers it serves and, in turn, to affected individuals and regulators. Those notices usually arrive weeks or months after an incident, and they tend to be the first reliable source of details such as the dates involved, the data types exposed and any credit monitoring offered. Until Praxis EMR says more, employees, patients and staff of its clients are left to watch for official communication.
If you are a current or former Praxis EMR employee, or a patient or staff member of a practice that uses its software, there is no need to assume your information was taken, but it is reasonable to stay alert. Keep an eye out for a letter, review explanation of benefits statements from your health insurer, and be careful with unexpected calls, texts or emails that mention your medical care. This page will be updated if Praxis EMR or a regulator publishes confirmed details about what happened.
When Did This Breach Occur?
Ransomware.live listed Praxis EMR as a victim of the Insomnia hacker group on October 5, 2026, and estimated the attack occurred on September 17, 2026. Praxis EMR has not confirmed when any intrusion began or when it was discovered, so the actual timeline of the incident remains unknown.
What Information Was Breached?
The kinds of data the hacker group claims to hold have not been published, and Praxis EMR has not confirmed that any information was taken. As an electronic medical records company, Praxis EMR may handle patient names, contact details, insurance information and health records, but whether any of it was involved has not been disclosed.
What You Can Do
If you are connected to Praxis EMR, consider these steps:
- Watch your mail and email for a notice from Praxis EMR or your healthcare provider, and keep any letter you receive.
- Review explanation of benefits statements and insurance activity for services you did not receive.
- Check your credit reports for free at annualcreditreport.com, and consider a fraud alert or credit freeze with Equifax, Experian and TransUnion.
- Be cautious with unexpected calls, texts or emails that mention your medical care, and confirm any request through a phone number you already trust.
- Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.
File a Data Breach Lawsuit Against Praxis EMR
If you are a current or former Praxis EMR employee, or a patient or staff member of a practice that uses its software, and you received notice about this incident or believe your information was exposed, you may have legal options. Healthcare technology companies are expected to safeguard the sensitive records entrusted to them, and a class action can help hold them accountable when they fail to do so.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.