---
title: "Ohio Dialysis Provider Breach Hits 8,000 Patien… | Firevault"
description: "Centers for Dialysis Care in Cleveland has confirmed a network breach exposing 8,000 patients and staff. Mark Fermor on why offline storage stops this cold."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/centers-for-dialysis-care-breach-exposes-8000-patients#webpage",
      "url": "https://fire-vault.com/news/centers-for-dialysis-care-breach-exposes-8000-patients",
      "name": "Ohio Dialysis Provider Breach Hits 8,000 Patien…",
      "description": "Centers for Dialysis Care in Cleveland has confirmed a network breach exposing 8,000 patients and staff. Mark Fermor on why offline storage stops this cold.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/f43b43e7-f005-4db4-a938-22c19a224c53/centers-for-dialysis-care-breach-exposes-8000-1752200000000-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/centers-for-dialysis-care-breach-exposes-8000-patients#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/centers-for-dialysis-care-breach-exposes-8000-patients#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Ohio Dialysis Provider Breach Hits 8,000 Patients",
          "item": "https://fire-vault.com/news/centers-for-dialysis-care-breach-exposes-8000-patients"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Ohio Dialysis Provider Breach Hits 8,000 Patients",
      "description": "Centers for Dialysis Care in Cleveland has confirmed a network breach exposing 8,000 patients and staff. Mark Fermor on why offline storage stops this cold.",
      "url": "https://fire-vault.com/news/centers-for-dialysis-care-breach-exposes-8000-patients",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/f43b43e7-f005-4db4-a938-22c19a224c53/centers-for-dialysis-care-breach-exposes-8000-1752200000000-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/f43b43e7-f005-4db4-a938-22c19a224c53/centers-for-dialysis-care-breach-exposes-8000-1752200000000-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/f43b43e7-f005-4db4-a938-22c19a224c53/centers-for-dialysis-care-breach-exposes-8000-1752200000000-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/f43b43e7-f005-4db4-a938-22c19a224c53/centers-for-dialysis-care-breach-exposes-8000-1752200000000-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-07-10T06:28:35.837663+00:00",
      "dateModified": "2026-08-11T21:29:24.285561+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/centers-for-dialysis-care-breach-exposes-8000-patients"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 484,
      "keywords": "Ohio, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "What Happened Centers for Dialysis Care, a non-profit provider based in Cleveland, Ohio, identified unauthorised access to its internal network on 20 March 2026. An unknown actor gained entry to files containing protected health information across the organisation's outpatient dialysis centres in Northeast Ohio. The provider has filed with the US Department of Health and Human Services and reporte",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What HappenedWhat Data Was ExposedWhy This MattersThe Offline AlternativeKey TakeawaysShareMore Resources

[Knowledge Vault](/learn/knowledge)/ Breach Analysis 

Breach Analysis · 10 July 2026 

# Ohio Dialysis Provider Breach Hits 8,000 Patients

Centers for Dialysis Care in Cleveland has confirmed a network breach exposing 8,000 patients and staff. Mark Fermor on why offline storage stops this cold.

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcenters-for-dialysis-care-breach-exposes-8000-patients)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcenters-for-dialysis-care-breach-exposes-8000-patients&text=Ohio%20Dialysis%20Provider%20Breach%20Hits%208%2C000%20Patients%0A%0ACenters%20for%20Dialysis%20Care%20in%20Cleveland%20has%20confirmed%20a%20network%20breach%20exposing%208%2C000%20patients%20and%20staff.%20Mark%20Fermor%20on%20why%20offline%20storage%20stops%20this%20cold.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcenters-for-dialysis-care-breach-exposes-8000-patients)[](mailto:?subject=Ohio%20Dialysis%20Provider%20Breach%20Hits%208%2C000%20Patients&body=Centers%20for%20Dialysis%20Care%20in%20Cleveland%20has%20confirmed%20a%20network%20breach%20exposing%208%2C000%20patients%20and%20staff.%20Mark%20Fermor%20on%20why%20offline%20storage%20stops%20this%20cold.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fcenters-for-dialysis-care-breach-exposes-8000-patients)

![Empty dialysis clinic corridor lit in cool blue and magenta, rows of vacant treatment chairs and equipment.](/__l5e/assets-v1/f43b43e7-f005-4db4-a938-22c19a224c53/centers-for-dialysis-care-breach-exposes-8000-1752200000000-2x.jpg)

Breach Analysis 

Article record

**Breach Analysis**Category 

**10 July 2026**Published 

**3 min read**Reading time 

**Mark Fermor**Written by 

Empty dialysis clinic corridor lit in cool blue and magenta, rows of vacant treatment chairs and equipment.

Why it matters

## What this means for organisations holding critical data

Centers for Dialysis Care in Cleveland has confirmed a network breach exposing 8,000 patients and staff. Mark Fermor on why offline storage stops this cold.

In this analysis

1.  01 [What Happened](#section-0)
2.  02 [What Data Was Exposed](#section-1)
3.  03 [Why This Matters](#section-2)
4.  04 [The Offline Alternative](#section-3)
5.  05 [Key Takeaways](#section-4)

**On this page**[What Happened](#section-0)[What Data Was Exposed](#section-1)[Why This Matters](#section-2)[The Offline Alternative](#section-3)[Key Takeaways](#section-4)

## What Happened

Centers for Dialysis Care, a non-profit provider based in Cleveland, Ohio, identified unauthorised access to its internal network on 20 March 2026. An unknown actor gained entry to files containing protected health information across the organisation's outpatient dialysis centres in Northeast Ohio.

The provider has filed with the US Department of Health and Human Services and reported that 8,000 individuals were affected. It has notified both HHS and the FBI, and engaged external cyber security experts to secure affected systems. At the time of reporting, no group has claimed responsibility and no ransom demand has been confirmed.

## What Data Was Exposed

The accessed files contained a wide range of sensitive personal and medical data belonging to patients and employees. Exposed categories include:

-   Full names and dates of birth
-   Social Security numbers
-   Medical information, healthcare treatment and diagnostic records
-   Health insurance information
-   Tax and financial information

Centers for Dialysis Care has advised affected individuals to monitor credit reports, account and benefit statements, and to report any suspicious activity to law enforcement and the state attorney general.

## Why This Matters

Protected health information is among the most sensitive data an individual holds. A combined leak of Social Security numbers, treatment records and financial data creates a long window for medical identity theft, insurance fraud and targeted phishing against patients who are already unwell.

Dialysis providers rely on continuous, scheduled treatment. Any disruption to systems, records or billing has direct clinical consequences. That makes healthcare networks a favoured target and makes the assumption that everything must sit on a live, connected server a serious liability.

Mark Fermor, founder of Firevault, said: "When a nonprofit clinic ends up in the same breach column as the biggest banks, it tells you the problem is not budget. It is architecture. If the record only exists on a machine that is always online, sooner or later somebody uninvited will read it."

## The Offline Alternative

Firevault Layer 1 places a [physical air gap](/offline-secure-storage/what-is-oss) between critical records and the public network. The storage device is powered down and mechanically disconnected until an authorised person needs it. There is no route from a compromised endpoint, phishing email or stolen credential to the archive, because there is no network path at all.

For a healthcare provider, that means patient histories, insurance files and financial records held in Firevault cannot be scraped by an intruder who has landed inside the corporate network. Live clinical systems still need protecting, but the definitive archive stops being part of the blast radius.

## Key Takeaways

-   **Healthcare is a prime target.** Combined medical, personal and financial data has a long resale life and is uniquely damaging to patients.
-   **Scale is not the shield.** An 8,000 patient nonprofit clinic faces the same attackers as national providers.
-   **Network reachable equals breach reachable.** If the archive is online, an intruder inside the network will eventually reach it.
-   **Physical air gap removes the path.** Firevault Layer 1 keeps the definitive record off the network entirely, so a corporate breach does not become a records breach.

About the author

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your data sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Command**Access windows and retrieval under your control 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)[

![Cornelius faces legal investigation after alleged Cl0p cyber attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/cornelius-alleged-clop-ransomware-data-breach-1786684482605.png)

Breach Analysis 

### Cornelius faces legal investigation after alleged Cl0p cyber attack

Cornelius faces legal scrutiny following reports of a Cl0p ransomware breach in August 2026. Claims suggest thousands of gigabytes of corporate data were compromised.

14 Aug 2026 4 min 







](/news/cornelius-alleged-clop-ransomware-data-breach)[

![Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg)

Breach Analysis 

### Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust

Delta Air Lines is investigating an unauthorised Wi-Fi network broadcast aboard Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that knocked passengers off the aircraft network. The lesson is not about aviation. It is about how easily a trusted connection can be impersonated.

13 Aug 2026 4 min 







](/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026)[

![Ransomware Attacks Spike 20% in July While AI Steals the Headlines](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg)

Breach Analysis 

### Ransomware Attacks Spike 20% in July While AI Steals the Headlines

Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology, pharmaceutical, medical billing and education organisations absorbed the sharpest increases.

12 Aug 2026 4 min 







](/news/ransomware-attacks-spike-july-2026-ai-distraction)

Share this article

Breach Analysis 10 July 2026 3 min read 

## Ohio Dialysis Provider Breach Hits 8,000 Patients

Centers for Dialysis Care in Cleveland has confirmed a network breach exposing 8,000 patients and staff. Mark Fermor on why offline storage stops this cold.

![Ohio Dialysis Provider Breach Hits 8,000 Patients](/__l5e/assets-v1/f43b43e7-f005-4db4-a938-22c19a224c53/centers-for-dialysis-care-breach-exposes-8000-1752200000000-2x.jpg)

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Published by Mark Fermor , Director & Co-Founder 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcenters-for-dialysis-care-breach-exposes-8000-patients)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcenters-for-dialysis-care-breach-exposes-8000-patients&text=Ohio%20Dialysis%20Provider%20Breach%20Hits%208%2C000%20Patients%0A%0ACenters%20for%20Dialysis%20Care%20in%20Cleveland%20has%20confirmed%20a%20network%20breach%20exposing%208%2C000%20patients%20and%20staff.%20Mark%20Fermor%20on%20why%20offline%20storage%20stops%20this%20cold.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcenters-for-dialysis-care-breach-exposes-8000-patients)[](mailto:?subject=Ohio%20Dialysis%20Provider%20Breach%20Hits%208%2C000%20Patients&body=Centers%20for%20Dialysis%20Care%20in%20Cleveland%20has%20confirmed%20a%20network%20breach%20exposing%208%2C000%20patients%20and%20staff.%20Mark%20Fermor%20on%20why%20offline%20storage%20stops%20this%20cold.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fcenters-for-dialysis-care-breach-exposes-8000-patients)

[Read full article](https://fire-vault.com/news/centers-for-dialysis-care-breach-exposes-8000-patients)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/offline-secure-storage/what-is-oss)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)