Almeida Law Group is investigating a data breach at Lake Region Healthcare Corporation. The breach occurred on May 19th, 2025 and was discovered on June 5th, 2026. If you were affected, contact Almeida Law Group.
About Lake Region Healthcare Corporation
Lake Region Healthcare Corporation is an independent, community-owned, non-profit healthcare organization headquartered in Fergus Falls, Minnesota. It operates two hospitals, ten clinics, a cancer center, a senior living community, and various other health and wellness services across nine communities in west central Minnesota and eastern North Dakota. Because the breach involved health and insurance records alongside personal identifiers, the potential exposure is particularly sensitive for the patients and community members it serves.
What Happened?
Lake Region Healthcare Corporation was listed in a Texas Attorney General data security breach report (record ID BR-0005157, published July 3rd, 2026). According to the filing, the breach occurred on May 19th, 2025 and was not discovered until June 5th, 2026 — a gap of more than twelve months. A total of 167,617 individuals were affected. Notification was provided by U.S. Mail. The types of information involved include names, addresses, Social Security numbers, dates of birth, medical information, and health insurance information.
The ransomware group known as “WorldLeaks” listed Lake Region Healthcare as a victim on a leak page, recording a compromise date of June 12th, 2025 — close to, but slightly after, the breach date reported to the Texas Attorney General. These dates may reflect different stages of the same incident. This is not the first cybersecurity event to affect the organization. Lake Region Healthcare experienced a ransomware attack in December 2020 that disrupted systems at multiple locations, a vendor data security incident through DMS Health Technologies in September 2023 affecting approximately 1,390 patients, and disruption stemming from the national Change Healthcare cybersecurity event in February 2024. This 2025 breach represents at least the fourth known security-related event in approximately five years. No class action lawsuits specifically connected to this incident were identified as of July 2026.
Key Facts at a Glance
- Company or Organization: Lake Region Healthcare Corporation
- Industry: Healthcare – Medical Provider (rural health system with hospitals, clinics, cancer center, and assisted living)
- Location: Fergus Falls, Minnesota 56537
- Incident type: Unauthorized access / ransomware (WorldLeaks threat group)
- Date of breach: May 19th, 2025
- Date breach discovered: June 5th, 2026
- Date of consumer notification: July 3rd, 2026 (published at Texas Attorney General website)
- Total persons affected: 167,617
- Prior breach: Yes — December 2020 ransomware attack; September 2023 vendor breach (DMS Health Technologies); February 2024 Change Healthcare disruption
- Litigation status: No class action lawsuits tied to this incident were found as of July 2026
- Source: Texas Attorney General data security breach report, BR-0005157 (https://oag.my.site.com/datasecuritybreachreport/apex/DataSecurityReportsPage#BR-0005157); RedPacket Security – WorldLeaks ransomware victim report (https://www.redpacketsecurity.com/worldleaks-ransomware-victim-lake-region-healthcare/); HIPAA Journal – Lake Region Healthcare ransomware attack (https://www.hipaajournal.com/lake-region-healthcare-recovering-from-ransomware-attack/); LRH – DMS Health Technologies vendor incident (https://www.lrhc.org/news/releases/data-security-incident-reported-by-imaging-vendor-for-lrh/)
What Should You Do?
If you received a notification letter from Lake Region Healthcare Corporation, review it carefully for any identity theft protection enrollment instructions and sign up before any stated deadline. Because this breach involved Social Security numbers, medical information, and health insurance information, you should also place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion), and monitor your credit reports regularly through AnnualCreditReport.com. Watch for unauthorized accounts or inquiries on your credit reports and review your Explanation of Benefits statements and medical records for any services you did not receive, which can be a sign of medical identity theft. If you suspect misuse of your information, report it at IdentityTheft.gov.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.