A Sensitive Touch Home Health;Alphastar Home Health Care;Heart of Texas Home Healthcare Se Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Three home-health providers— A Sensitive Touch Home Health, Alphastar Home Health Care, and Heart of Texas Home Healthcare—were listed by the Everest ransomware group on November 15, 2024, after internal files were exfiltrated. Anyone who received services from these organizations should review any notices they receive and take steps to protect their personal information.
People who have received care from A Sensitive Touch Home Health, Alphastar Home Health Care, or Heart of Texas Home Healthcare Se may now face the practical risk that their medical records and personal details have left the organizations’ control. When a ransomware group claims to hold internal files from home-health providers, the immediate concern for patients and families is whether sensitive health information, contact details, or identifiers could be misused for fraud, identity theft, or unwanted contact.
Public reporting on 15 November 2024 stated that the three related entities had been listed by the Everest ransomware group. The listing asserts that internal files were taken in a ransomware attack and that those files include medical records and personal information. The number of people affected remains unknown, and many operational details of the incident have not been disclosed.
Inside the incident
According to the available public record, the Everest ransomware group listed A Sensitive Touch Home Health, Alphastar Home Health Care, and Heart of Texas Home Healthcare Se on its leak site on or about 15 November 2024. The group claims that internal files were exfiltrated during a ransomware attack and that the material includes medical records and personal information. The listing also contains a standard demand that a company representative contact the group “before time runs out.”
No confirmed figure for the number of individuals whose data may be involved has been published. The precise method of initial access, the duration of any unauthorized presence on the networks, and the full volume of data taken have not been disclosed in the public reporting. The incident is therefore known primarily through the group’s own claim rather than through an independent forensic confirmation released by the organizations.
Inside everest
Everest is a ransomware operation that has appeared repeatedly on public leak sites in recent years. Like many contemporary ransomware groups, it typically employs a double-extortion model: encrypting systems while also copying data and threatening to publish or sell it if a ransom is not paid. The group maintains a dedicated leak site on which it posts the names of claimed victims, sample files, and countdown timers. Public reporting on earlier Everest campaigns has shown that the group often targets organizations that hold large volumes of personal or regulated data, including healthcare and professional-services firms.
In this case the only specific assertion about these three home-health entities is the listing itself and the accompanying claim that medical records and personal information were among the internal files taken. No independent verification of the volume, exact contents, or authenticity of any sample files has been supplied in the public record. The listing should therefore be treated as an unverified claim by the threat actor.
A Sensitive Touch Home Health;Alphastar Home Health Care;Heart of Texas Home Healthcare Se and its sector
A Sensitive Touch Home Health, Alphastar Home Health Care, and Heart of Texas Home Healthcare Se operate in the home-health sector, providing medical and personal-care services to patients in their residences. Organizations of this type routinely collect and store protected health information, insurance details, contact data for patients and family members, and administrative records required for billing and regulatory compliance.
Because home-health providers handle data that is both medically sensitive and personally identifying, any unauthorized access carries heightened consequences. Patients often include elderly or medically vulnerable individuals whose records may contain diagnoses, medication lists, Social Security numbers, and home addresses. A breach in this sector can therefore expose information that is difficult to change and that retains value for identity fraud long after the initial incident.
What was likely exposed
The public facts state only that “internal files” were exfiltrated and that the group claims those files include medical records and personal information. No inventory of specific data fields, file counts, or patient totals has been released. Organizations in the home-health sector typically maintain electronic health records, intake forms, insurance authorizations, staff credentials, and billing databases. Whether any or all of those categories were present in the material claimed by Everest remains unconfirmed.
Until the organizations or an independent investigation publish a more precise description, the exact contents of the exfiltrated files cannot be stated as fact. The only confirmed public detail is the group’s assertion that medical records and personal information form part of the haul.
What's at stake
For individuals whose data may be involved, the concrete risks include identity theft, medical-identity fraud, targeted phishing, and the unwanted disclosure of private health conditions. Stolen medical records can be used to open fraudulent insurance claims or to craft highly convincing social-engineering messages. Personal identifiers such as names, addresses, dates of birth, and Social Security numbers remain useful to criminals for years.
For the organizations themselves, the incident raises regulatory, operational, and reputational considerations. Healthcare entities are subject to data-protection rules that may require notification of affected individuals and regulators once the scope of any breach is established. Service continuity can also be disrupted if systems were encrypted or if staff must divert time to incident response.
- Patients may need to monitor credit reports and medical-billing statements for unexpected activity.
- Family members listed as emergency contacts could receive phishing attempts that reference real care details.
- The organizations face potential notification obligations and the cost of forensic review and patient support.
- Any published data could remain available to other criminals even after the original listing is removed.
Were you affected?
If you or a family member have received services from A Sensitive Touch Home Health, Alphastar Home Health Care, or Heart of Texas Home Healthcare Se, treat the possibility of exposure seriously until official notifications clarify the scope. Practical first steps include placing a fraud alert with the major credit bureaus, reviewing Explanation-of-Benefits statements for unfamiliar claims, and being cautious of unsolicited calls or emails that reference your care. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Official updates from the organizations or from state health authorities remain the most reliable source of confirmation about whether your specific records were involved.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Total Patient Care LLC;A Sensitive Touch Home Health;Alphastar Home Health Care;Heart of T Listed by everest Ransomware GroupArtistic Family Dental;Value Dental Center;Sparkling Smiles Family Dentistry Listed by everest Ransomware GroupMCNA Dental 1 million patients records Listed by everest Ransomware Group2K Dental Listed by everest Ransomware GroupLatest breaches
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.