Central Ohio Primary Care Data Breach

Alleged

Ransomware claim involving Central Ohio Primary Care.

Published: Aug 25, 2026 Chaos
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Central Ohio Primary Care
Industry
Business Services
Threat Actor
Chaos
Date of Incident
Aug 25, 2026

Executive Summary

Central Ohio Primary Care, a primary care provider based in the United States, was listed on the dark web leak portal of the Chaos ransomware group on August 25, 2026. SOCRadar’s Dark Web Monitoring service identified this listing. The organization’s patient-facing infrastructure includes mychart.copcp[.]com, a portal used for appointment management, accessing health records, and patient communications. This incident is particularly concerning given the sensitive nature of patient data handled by healthcare providers. In the 60 days preceding this listing, the Chaos ransomware group claimed 15 other victims, primarily targeting organizations in the Healthcare, Technology, and Professional Services sectors across the United States, the United Kingdom, and East Asia. Recent victims with similar profiles to Central Ohio Primary Care include MS Walker, Park de Rochie, Tomorrow’s Office, and Healthcare Highways. This targeting aligns with the group’s known focus on US-based healthcare organizations.

Technical Analysis

SOCRadar’s stealer-log query for copcp[.]com returned 25 records. Of these, 18 specifically targeted the patient portal at mychart.copcp[.]com. The usernames in these records were predominantly consumer email addresses, suggesting a focus on patient account takeovers rather than corporate network access. One record associated an @copcp[.]com username with a Netflix credential, indicating a potential compromise of an employee’s workstation. Additionally, two records showed corporate and partner-domain usernames accessing internal authentication endpoints. The freshness window for these records is from July 28 to August 25, 2026, with the most recent entries dated August 25, the same day as the Chaos listing. The presence of fresh records dated to the listing day indicates active credential harvesting rather than the resale of aged logs. For ransomware groups like Chaos, infostealer credentials serve as a primary initial access vector. Threat actors often source these credentials, validate corporate accounts, and use them to gain access to internal systems before deploying ransomware. While these specific compromised credentials have not been definitively confirmed as Chaos’s entry point, the combination of active workstation compromise and patient portal account takeover, with records aligning to the listing date, elevates this incident to a high-priority investigation. The volume of patient portal credentials also raises significant direct HIPAA concerns. Given these findings, CTI and compliance teams should immediately initiate a breach notification assessment and review patient communication procedures. Continued dark web and stealer-log monitoring, proactive credential hygiene checks, password rotation, and multi-factor authentication reviews are recommended. Monitoring alternate corporate domains and reviewing Microsoft 365, VPN, and remote-access activity are also crucial steps.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.