Hospital Episcopal San Lucas Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Hospital Episcopal San Lucas was listed by the Medusa ransomware group on September 4, 2024, after internal files were exfiltrated in a ransomware attack; the date of the actual intrusion has not been established. Anyone who received care or worked at the hospital should review their personal information for signs of misuse and follow the facility’s guidance on protective steps.
Ransomware groups continue to target healthcare providers worldwide, exploiting the sector’s reliance on continuous operations and sensitive records. In this landscape, listings on criminal leak sites have become a common way for attackers to pressure victims and advertise their work. One such claim involves Hospital Episcopal San Lucas of Ponce, Puerto Rico, which appeared on the Medusa ransomware group’s site in early September 2024.
Public reporting indicates that the group asserts it exfiltrated internal files totaling 309 GB during a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope is limited. For patients, staff, and partners of a regional hospital, any unauthorized access to internal material raises practical concerns about privacy and operational continuity.
Inside the incident
According to available records, Hospital Episcopal San Lucas was listed by the Medusa ransomware group on or around September 4, 2024. The listing describes an attack in which internal files were allegedly exfiltrated, with the total volume of data claimed at 309.00 GB. No further public detail has been provided on the precise date of intrusion, the initial access method, or whether systems were encrypted in addition to data theft. The number of individuals whose information may be involved is listed as unknown. The hospital’s corporate office is recorded at PO Box 2027, Ponce, Puerto Rico 00733, and the organization is noted as employing 131 people. Beyond the group’s claim and these basic organizational facts, public information about the incident itself remains limited.
Inside medusa
Medusa is a ransomware operation that has been active for several years and is known for a double-extortion model. After gaining access to a network, the group typically steals data before deploying encryption and then threatens to publish the stolen material on a dedicated leak site if a ransom is not paid. Listings on that site serve both as pressure on the victim and as advertising for the group’s capabilities. Medusa has previously claimed attacks against organizations across multiple sectors, including healthcare, manufacturing, and education. In this case, the appearance of Hospital Episcopal San Lucas on the leak site constitutes a claim by the group; independent verification of the full contents or the success of any encryption component has not been publicly detailed in the available record.
Who is Hospital Episcopal San Lucas?
Hospital Episcopal San Lucas, also known as Hospital San Lucas, is a hospital located in Ponce, Puerto Rico. It operates as a healthcare provider serving the local community and surrounding areas. Like most hospitals, it maintains clinical, administrative, and operational systems that support patient care, staffing, and billing. Organizations of this type routinely handle large volumes of sensitive information because medical treatment requires detailed personal and health records. A breach claim against such an institution is consequential because disruption or exposure can affect both the continuity of care and the privacy of individuals who have sought treatment or worked at the facility. The hospital’s modest reported staff size of 131 employees underscores its role as a regional rather than national provider, yet the sensitivity of healthcare data remains high regardless of scale.
The information in question
The available facts state that internal files were exfiltrated in a ransomware attack and that the total volume claimed is 309 GB. No more granular inventory of file types, patient records, employee data, or other categories has been publicly disclosed. Healthcare organizations typically hold medical histories, contact details, insurance information, and administrative documents; however, it is not confirmed which, if any, of those categories are present in the material Medusa claims to possess. Because the exact contents remain unconfirmed, any assessment of what was taken must stay within the stated description of “internal files.”
The real-world impact
For individuals whose information may have been among the exfiltrated files, the primary risks include potential misuse of personal or medical details for identity fraud, targeted phishing, or unauthorized disclosure of private health matters. Even when the precise data types are unknown, the presence of internal hospital files creates a realistic possibility that some combination of administrative and clinical material is involved. For the hospital itself, the incident can mean operational strain, the need to investigate and contain any remaining access, notification obligations under applicable privacy rules, and reputational effects that may influence patient trust. Because the number of people affected is unknown, the full scale of individual impact cannot yet be measured. The 309 GB figure indicates a substantial volume of material, which in practice can contain many thousands of documents, yet volume alone does not establish how many people are represented.
If your data was in this claimed breach
If you have been a patient, employee, or partner of Hospital Episcopal San Lucas, treat the claim as a reason for heightened caution rather than confirmed personal exposure. Monitor financial and medical accounts for unexpected activity, be alert to phishing messages that reference the hospital or medical services, and consider placing fraud alerts with credit bureaus if you believe sensitive identifiers may have been involved. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Keep records of any unusual contacts and report confirmed identity theft to the appropriate authorities. Public detail on this incident remains limited, so continued attention to official notices from the hospital or regulators is advisable.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
United Sleep Diagnostics Listed by medusa Ransomware GroupAmerican Medical Billing Listed by medusa Ransomware GroupH&H Group Listed by medusa Ransomware GroupHealth People Listed by medusa Ransomware GroupLatest breaches
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.