Almeida Law Group is investigating a data breach at Midwest Spine & Brain Institute. If you were affected, contact Almeida Law Group.
About Midwest Spine & Brain Institute
Midwest Spine & Brain Institute (MSBI) is an independent medical clinic established in 1987 and based in Minnesota, with 13 locations across the Minneapolis–St. Paul metro area and western Wisconsin. It specializes in spinal and neurological care, offering services such as spinal fusion, scoliosis correction, total disc replacement, skull base surgery, and brain tumor surgery. Because MSBI provides direct medical care, it handles protected health information and sensitive personal data for tens of thousands of patients.
What Happened?
Midwest Spine & Brain Institute was listed in an HHS Office for Civil Rights breach portal report submitted on August 14th, 2026, identifying an unauthorized access and disclosure incident affecting 108,487 individuals. The breached information was located on a network server and other systems, and a business associate was present.
The breach did not originate within MSBI’s own network. Instead, an unauthorized actor gained access to the systems of MSBI’s third-party managed service provider, 3C Care Systems LLC, a healthcare IT company specializing in workflow automation, cloud-hosted platforms, and data integration, on or about November 21st, 2024. MSBI’s investigation concluded on June 18th, 2026—approximately 19 months after the initial intrusion—that protected health information (PHI) and personally identifiable information (PII) were potentially involved. According to MSBI’s notification letters and a Massachusetts Attorney General filing, the exposed data included full names, dates of birth, Social Security numbers, and medical records including medical treatment information. MSBI confirmed that its own larger network was not impacted; only data that had been provided to 3C Care Systems was affected. At the time of notification, no actual or attempted misuse of the impacted data had been identified. MSBI is offering complimentary single-bureau credit monitoring to affected individuals.
HIPAA Journal has reported that the incident appears to have involved a ransomware attack by the RansomHub ransomware group, which claimed on its dark-web leak site—first observed on November 19th, 2024—to have exfiltrated 100 GB of data from 3C Care Systems. Those claims remain unverified attacker allegations; MSBI’s own notification letters did not name a specific threat actor or describe the attack as ransomware, and 3C Care Systems has not issued a public statement about the incident. RansomHub has since disbanded, with its infrastructure reportedly taken over by another group, DragonForce, in March 2025. Multiple law firms, including ClassAction.org and Strauss Borrelli PLLC, are investigating whether a class action lawsuit can be filed on behalf of affected individuals, though no lawsuit has been filed as of this writing.
Key Facts at a Glance
- Company or Organization: Midwest Spine & Brain Institute
- Industry: Healthcare Provider – Spine and Neurosurgery
- Location: Minnesota (Minneapolis–St. Paul metro area and western Wisconsin)
- Incident type: Unauthorized Access/Disclosure
- Date of breach: November 21st, 2024
- Date breach discovered: June 18th, 2026
- Date of consumer notification: August 14th, 2026
- Total persons affected: 108,487
- Identity theft protection offered: Complimentary single-bureau credit monitoring
- Litigation status: No lawsuit filed; class action investigations underway by multiple law firms
- Source: HHS OCR Breach Portal, HIPAA Journal, Massachusetts Attorney General filing, ClassAction.org, ClaimDepot
What Should You Do?
If you received a notification from Midwest Spine & Brain Institute, enroll in the complimentary credit monitoring being offered and take note of any enrollment deadline included in your letter. Because Social Security numbers and medical records were among the data types exposed, you should also consider placing a fraud alert or credit freeze with the three major credit bureaus and reviewing your credit reports for unfamiliar accounts at AnnualCreditReport.com. Monitor your Explanation of Benefits statements and medical records for any services you did not receive, which could indicate medical identity theft. If you identify suspicious activity, report it at IdentityTheft.gov, where you can also build a personalized recovery plan.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.