LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › OnePoint Patient Care Listed by incransom Ransomware Group

HIGH severityUnverified claimHow we verify

OnePoint Patient Care Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 6, 2024
OnePoint Patient Care Listed by incransom Ransomware Group

Reported August 6, 2024.

HIGH
Severity
August 6, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The OnePoint Patient Care Listed by incransom Ransomware Group (reported August 6, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to single out healthcare and pharmacy providers because the data they hold is both sensitive and operationally critical, creating strong pressure to pay. Against that backdrop, OnePoint Patient Care appeared on the leak site of the incransom ransomware group on 6 August 2024. Public reporting states only that internal files were exfiltrated; the number of people affected remains unknown and further technical details have not been released. For patients, families and staff who rely on hospice pharmacy services, even an unconfirmed listing raises immediate questions about what may have left the organisation’s systems.

This article sets out only what has been reported, places the claim in context, and outlines practical steps for anyone who may be concerned.

Breaking down the breach

On 6 August 2024, OnePoint Patient Care was listed by the incransom ransomware group. The group’s claim states that internal files were exfiltrated during a ransomware attack. No public confirmation of the intrusion method, the precise date of compromise, the volume of data taken, or any encryption of systems has been issued by the organisation or by independent investigators. The number of individuals potentially affected is listed as unknown. Beyond the group’s assertion that internal files were removed, no further verified details about the incident itself have been disclosed.

Who is incransom?

Incransom is a ransomware operation that has been active since at least 2023. Like many contemporary groups, it typically follows a double-extortion model: data is first stolen, then systems may be encrypted, after which the victim is threatened with public release of the material unless a ransom is paid. The group maintains a dark-web leak site where it posts the names of organisations it claims to have compromised, sometimes accompanied by sample files. Listings are marketing claims intended to increase pressure; they are not independent proof that every asserted detail is accurate. Incransom has previously named victims across multiple sectors, including healthcare and professional services, but no additional statements specific to OnePoint Patient Care beyond the listing itself have been made public.

Who is OnePoint Patient Care?

OnePoint Patient Care, also referred to as OPPC, was founded in 1965 and is headquartered in Tempe, Arizona. It operates as a national, hospice-focused pharmacy that combines medication delivery, mail-order services and Pharmacy Benefit Management under a single umbrella. Organisations of this type routinely handle prescriptions, patient medication histories, insurance and billing records, and communications with hospice providers and families. Because hospice care involves medically fragile individuals and often spans multiple care settings, the confidentiality and integrity of those records are essential both to clinical safety and to regulatory compliance. A ransomware claim against such a provider therefore carries heightened significance even when the full scope remains unconfirmed.

What was likely exposed

The only data category named in public reporting is “internal files exfiltrated in ransomware attack.” No inventory of specific document types, databases or record counts has been released. Pharmacy and hospice-support organisations commonly maintain patient identifiers, prescription histories, insurance details, clinical notes shared with hospice teams, employee records and internal operational documents. Whether any of those categories were among the files claimed by incransom is unconfirmed. Until the organisation or a regulatory filing provides a clearer description, the exact contents of the exfiltrated material remain unknown.

What's at stake

If personal or clinical information was included among the internal files, affected individuals could face risks of medical identity theft, fraudulent prescription activity, targeted phishing that references genuine care details, or unsolicited contact that exploits knowledge of a loved one’s hospice status. For the organisation itself, the consequences may include regulatory scrutiny under health-privacy rules, disruption of pharmacy operations, and the need to notify patients and partners once the scope is better understood. Because the number of people affected is still listed as unknown, the practical scale of these risks cannot yet be quantified. The absence of confirmed encryption details also leaves open the possibility that operational systems were or were not locked; that question remains unanswered in public sources.

What to do if you're exposed

Anyone who has received services from OnePoint Patient Care or whose family member has done so should treat the listing as a reason for heightened caution rather than confirmed personal compromise. Monitor bank and insurance statements for unfamiliar pharmacy charges, place a fraud alert with the major credit bureaus if identity documents may have been involved, and be sceptical of unexpected emails or calls that reference hospice or medication details. Request a free credit report and review it carefully. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. If OnePoint Patient Care issues official notification letters or a public statement, follow the specific guidance those communications provide, including any offer of credit monitoring. Document any suspicious activity and report it promptly to the organisation and to the relevant consumer-protection agencies.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyOnePoint Patient Care security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See OnePoint Patient Care’s full breach history →

More recent breaches

Community Connections Listed by incransom Ransomware GroupApril 4, 2026Onecare Listed by incransom Ransomware GroupDecember 15, 2024Primary Health Services Center Listed by incransom Ransomware GroupNovember 28, 2024Imperial Valley Respite (ivrespite.com) Listed by incransom Ransomware GroupNovember 3, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the OnePoint Patient Care Listed by incransom Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by incransom — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram