CiberLATAMbywhalemate

U.S. hospitals report data incidents

Grafton City Hospital notified 1,215 people after a phishing-linked breach. Cedar County Memorial is still investigating a possible data exposure.

Whalemate Labs · AI-assisted researchPublished:3 min read

Grafton City Hospital in West Virginia notified 1,215 people after a cybersecurity incident exposed part of their protected health information. The incident stemmed from a phishing-compromised email account on May 6, 2026, according to a data security notice cited by Wilshire Law Firm. The affected entity was Monongalia County General Hospital Company, part of the Vandalia Health network.

Grafton City Hospital in West Virginia notified 1,215 people after a cybersecurity incident exposed part of their protected health information. The incident began with an email account compromised through phishing on May 6, 2026, according to a data security notice cited by Wilshire Law Firm. The affected entity was Monongalia County General Hospital Company, part of the Vandalia Health network.

What is known about the Grafton City Hospital case?

The incident affected 1,215 people and was tied to a compromised email account, according to the notice cited by Wilshire Law Firm. The report also says the hospital is affiliated with Mon Health, part of Vandalia Health, and that protected health information was exposed.

A reference from Black Hat News Tokyo also says Grafton City Hospital notified affected people after a cybersecurity incident and traces the intrusion to phishing. In both accounts, the key point is that this was not an abstract leak, but a specific account that became the access point.

What did Cedar County Memorial Hospital report?

Cedar County Memorial Hospital said on September 10, 2026, that its investigation was still underway and that it had not yet determined the scope of a possible patient data exposure. According to HIPAA Journal, the hospital said it will notify affected individuals only after it completes the analysis.

The information available so far does not show how many records were compromised or confirm the final scale of the incident. The review remains open, so the picture is still preliminary.

How does this connect to the Change Healthcare case?

Andrew Witty, chief executive of UnitedHealth Group, told the U.S. Congress that attackers in the Change Healthcare case were paid $22 million in cryptocurrency. VCPost later picked up that admission and linked it to financial and operational pressure on the health payments chain in the United States.

Two years after the attack, MedCity News argued that the episode exposed a structural weakness in the medical payment and authorization clearinghouse model. According to that analysis, much of the ecosystem depended on a single actor without enough redundancy, and that resilience problem remains.

Sources

View all