News
TheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data BreachOpenLoop Health Telehealth Infrastructure Vendor Breach Exposes Patient Data Across Multiple Digital Health Clients · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data BreachOpenLoop Health Telehealth Infrastructure Vendor Breach Exposes Patient Data Across Multiple Digital Health Clients · Data Breach

Data Breach

TheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care

TL;DR

A ransomware group called TheGentlemen has claimed an attack on Advantage Home Health Care. The volume of affected records has not been confirmed. Home health agencies are HIPAA-covered entities, and a ransomware claim of this type typically triggers breach notification duties and OCR reporting obligations.

A ransomware group called TheGentlemen has claimed an attack on Advantage Home Health Care. The volume of affected records has not been confirmed. Home health agencies are HIPAA-covered entities, and a ransomware claim of this type typically triggers breach notification duties and OCR reporting obligations.

Threat intelligence tracker BreachSense logged a ransomware claim by 'TheGentlemen' against Advantage Home Health Care on July 20, 2026. Here is what compliance officers and home health administrators need to know now.

medcomply.ai editorial teamPublished July 21, 2026Updated July 21, 20265 min read

A ransomware group named TheGentlemen has publicly claimed an attack on Advantage Home Health Care, a U.S.-based home health agency, with the claim logged by threat intelligence platform BreachSense on July 20, 2026.

This is a breach incident, not an OCR enforcement action. No fine has been announced, and no regulatory finding has been made at this time.

The number of patients or records affected has not been publicly confirmed. Until Advantage Home Health Care or a regulatory authority releases verified figures, any specific record count should be treated as unverified.

What TheGentlemen Claim and What It Means

Ransomware groups typically follow a recognizable pattern: gain access to a network, encrypt files, exfiltrate data, and then publicly claim the attack to pressure the victim into paying a ransom. The public claim on BreachSense is the first visible step in that pattern.

MedComply.ai has covered this playbook before in incidents involving organizations such as Hillebrand and the Texas Hearing Institute. The claim alone does not confirm that patient data was exfiltrated, but it is a serious signal that warrants immediate investigation.

Warning

Under HHS guidance, a ransomware attack is presumed to be a HIPAA breach unless the covered entity can demonstrate through a documented four-factor risk assessment that there is a low probability PHI was compromised. The burden of proof falls on the organization, not on regulators.

Why Home Health Agencies Are High-Value Targets

Home health agencies sit at the intersection of clinical care and community access. Their records routinely include:

  • Clinical notes and visit documentation
  • Diagnoses and treatment plans
  • Medication lists and physician orders
  • Social Security numbers collected for billing
  • Medicare and Medicaid beneficiary identifiers

This combination of sensitive personal and medical data makes home health agencies attractive targets. Exfiltrated records from a single agency can affect a large number of vulnerable patients, many of them elderly or disabled, who may be less equipped to monitor for identity theft or fraud.

HIPAA Obligations That Apply Now

Advantage Home Health Care is a HIPAA-covered entity. If the incident involved unauthorized access to protected health information, several regulatory obligations apply.

Breach Notification to Individuals

Covered entities must notify each affected individual without unreasonable delay and no later than 60 calendar days after the breach is discovered. 45 CFR §164.404

Notification to HHS

If the breach affects 500 or more individuals, the organization must notify the Secretary of HHS simultaneously with individual notifications. Breaches affecting fewer than 500 individuals may be reported on an annual log. 45 CFR §164.408

Media Notification

For breaches affecting 500 or more residents of a single state or jurisdiction, the covered entity must also notify prominent media outlets in that area. 45 CFR §164.406

The Risk Assessment Presumption

HHS guidance makes clear that ransomware incidents trigger a presumption of breach. Avoiding breach notification requires a completed and documented four-factor risk assessment showing low probability of PHI compromise. That assessment must address the nature and extent of the PHI involved, the identity of the unauthorized person, whether PHI was actually acquired or viewed, and the extent to which risk has been mitigated. 45 CFR §164.402

What Compliance Officers and Administrators Should Watch For

If you work in home health or advise organizations in this space, this claim is a useful prompt to review several fundamentals:

  • Is your incident response plan current and has it been tested?
  • Does your organization have a documented ransomware response protocol that includes the HHS risk assessment framework?
  • Are backup systems isolated from primary networks so that encrypted data can be restored without paying a ransom?
  • Does your Business Associate Agreement inventory cover every vendor with access to PHI, including remote monitoring and scheduling software?

The HIPAA Security Rule requires covered entities to implement policies and procedures to address security incidents, including responses to suspected or known security incidents. 45 CFR §164.308(a)(6)

What Comes Next

MedComply.ai will monitor this situation for any official statement from Advantage Home Health Care, any HHS breach portal filing, or any further detail from threat intelligence sources. As with similar ransomware claims covered on this site, the gap between a public group claim and a confirmed organizational disclosure can range from days to weeks.

Compliance officers at home health agencies should treat this incident as a timely reminder: the clock on breach notification obligations starts running from the date of discovery, not from the date a public claim appears.

TheGentlemen ransomware group has claimed an attack on Advantage Home Health Care as of July 20, 2026. The record count is unconfirmed. Home health agencies are HIPAA-covered entities, and a ransomware claim of this kind triggers a presumption of breach under HHS guidance. Organizations in this space should review their incident response plans and ensure their breach notification timelines under 45 CFR §164.404 are clearly understood.

Sources & citations

  • BreachSense Breach TrackerOpen

All content verified against official HHS guidance and the Code of Federal Regulations.

Frequently asked questions

Is this a confirmed data breach or just a ransomware group claim?
As of the discovery date of July 20, 2026, this is a claim logged by threat intelligence tracker BreachSense. The volume of records exposed and whether patient PHI was exfiltrated have not been publicly confirmed by Advantage Home Health Care or any regulatory authority.
Are home health agencies required to follow HIPAA breach notification rules?
Yes. Home health agencies are HIPAA-covered entities. If a ransomware incident results in unauthorized access to protected health information, the agency must notify affected individuals, the Department of Health and Human Services, and in some cases the media, under the HIPAA Breach Notification Rule.
What kinds of PHI do home health agencies typically hold?
Home health agencies routinely maintain clinical notes, diagnoses, medication records, treatment plans, and in many cases Social Security numbers and financial information. This makes them high-value targets for ransomware groups seeking leverage or saleable data.
Does a ransomware attack automatically count as a HIPAA breach?
Under HHS guidance issued in 2022, a ransomware attack is presumed to involve a breach of unsecured PHI unless the covered entity can demonstrate a low probability that PHI was compromised through a four-factor risk assessment. The burden of proof sits with the organization.
What should Advantage Home Health Care do right now if this claim is accurate?
The organization should activate its incident response plan, conduct a risk assessment to determine the scope of PHI exposure, engage legal counsel experienced in HIPAA, and preserve forensic evidence. If the risk assessment cannot rule out PHI compromise, breach notification timelines under 45 CFR §164.404 begin to run from the date the breach was discovered.

Not legal advice. medcomply.ai provides compliance intelligence for educational and operational planning. Consult qualified counsel for legal interpretation.