Incident

Mail processing vendor Renkim hit by ransomware, exposing data of Ballad Health patients


Learn More

Renkim, a third-party electronic print and mail processing service provider for Ballad Health, was hit by a cyberattack that resulted in unauthorized access to personal information of healthcare patients. The breach, which occurred in early March 2025, exposed sensitive data including Social Security numbers and healthcare-related information through the vendor's compromised network systems.

Renkim detected suspicious activity on its network on March 3, 2025. The company isolated the affected systems and engaged third-party cybersecurity experts to conduct an investigation.

The incident was caused by  result of a ransomware attack conducted by the Inc. Ransom gang. The cyberattack affected 46,592 individuals. Exposed data includes:

  • Full names
  • Contact information including addresses and phone numbers
  • Social Security numbers (in limited cases)
  • Dates of birth (in some instances)
  • Client names and account numbers
  • Dates of medical services
  • Healthcare client information processed for mailings

Notification letters are being mailed to all affected persons for whom Renkim has current address information. The company has established a dedicated helpline at 1-866-461-3496 for individuals with questions or concerns about the breach. 

Mail processing vendor Renkim hit by ransomware, exposing data of Ballad Health patients