Long hospital corridor with fluorescent lighting and medical equipment
Photo via Unsplash

TL;DR: Texas Tech University Health Sciences Center (TTUHSC) just disclosed that 813,892 patients at its El Paso campus had their medical records, Social Security numbers, financial data, and health insurance information stolen in a September 2024 ransomware attack. The Interlock ransomware group claimed responsibility in October 2024 and dumped 2.6 terabytes of data on the dark web. Combined with 650,000 victims at the Lubbock campus disclosed earlier, the total breach now exceeds 1.46 million patients. The university took 19 months from breach to full notification, and the stolen data has been publicly available online for over a year.

What Took So Long?

Between September 17 and September 29, 2024, attackers had free run of TTUHSC's network. Twelve days inside the systems of one of the largest academic health centers in the western United States. No alarm tripped fast enough to stop them [1][2].

TTUHSC detected "technology issues" during the attack window, but the phrase does the real damage a disservice. The Interlock ransomware group didn't just encrypt files. They exfiltrated 2.1 million files totaling 2.6 terabytes of data before anyone pulled the plug [2][3].

That's not a technology issue. That's the entire patient database walking out the door.

On October 27, 2024, Interlock posted the stolen data on its dark web leak site. The records were available for anyone with a Tor browser to download. TTUHSC's patients had no idea [2].

The Lubbock campus disclosed its portion (650,000 patients) in January 2025, four months after the attack. But the El Paso campus? That disclosure came in April 2026. Nineteen months after attackers walked away with the data. Seventeen months after that data was posted publicly online [4].

Everything a Medical Identity Thief Could Want

The data TTUHSC confirmed as compromised reads like a checklist for medical identity fraud [1][3]:

  • Full names and dates of birth
  • Home addresses
  • Social Security numbers
  • Driver's license and government ID numbers
  • Financial account information
  • Health insurance information
  • Medical record numbers
  • Billing and claims data
  • Diagnosis and treatment information

This isn't like having your email address leak. Medical records contain information you can't change. Your diagnosis history, your treatments, your insurance claims: that data follows you for life. And unlike a stolen credit card number, you can't call a hotline and get a new medical history.

Medical identity theft is particularly dangerous because it can alter your health records. Criminals who use your insurance to receive treatment can contaminate your file with their blood type, allergies, and medications. That contamination can be life-threatening if you later receive emergency care based on a record that isn't yours.

Who Is Interlock?

Interlock is a ransomware group that first appeared in September 2024, right around the time it hit TTUHSC. The group operates a double-extortion model: steal the data first, encrypt the systems second, then demand payment for both the decryption key and a promise not to publish the stolen files [2].

TTUHSC apparently didn't pay. Interlock dumped everything on October 27, 2024 [2].

The group gained initial access by "leveraging a commercial Internet Service Provider's vendor infrastructure," according to the university's own disclosure: a polished way of saying a vendor's systems were compromised and used as a springboard into TTUHSC's network [3].

Once inside, the attackers had twelve days to move laterally across the HSC network, locate patient databases, and exfiltrate 2.6 terabytes without detection. That's roughly 650 feature-length movies' worth of data flowing out of a hospital system. Nobody noticed.

The 19-Month Notification Timeline

Here's how this played out, in order:

  • September 17-29, 2024: Attackers inside TTUHSC's network. Systems disrupted for approximately three weeks [1][3].
  • October 27, 2024: Interlock claims responsibility and publishes 2.6TB of stolen data on the dark web [2].
  • December 2024: TTUHSC reports the breach to the U.S. Department of Health and Human Services [1].
  • January 2025: Lubbock campus victims (650,000) begin receiving notification letters [1].
  • April 2026: El Paso campus victims (813,892) finally disclosed. State attorney general offices notified [4].

Under HIPAA, healthcare providers must notify affected individuals within 60 days of discovering a breach. TTUHSC disclosed the Lubbock campus portion within that window. But the El Paso disclosure came 19 months after the breach and 17 months after the data was already circulating on the dark web.

TTUHSC says it "recently concluded its investigation" into the El Paso campus data [4]. That investigation took a year and a half while stolen medical records sat on the open internet.

1.46 Million Patients. One Ransomware Group. Zero Real-Time Alerts.

The combined numbers tell the story:

  • 650,000 patients at the Lubbock campus
  • 813,892 patients at the El Paso campus
  • 1.46 million total patients with medical records compromised
  • 2.6 terabytes of data exfiltrated
  • 12 days of undetected attacker access
  • 3 weeks of system outages

TTUHSC isn't a small clinic. It's one of the largest health sciences university systems in Texas, operating medical schools, nursing schools, and health services across the western half of the state. The El Paso campus alone serves a border community of nearly a million people.

And this is what happens when real-time monitoring fails and breach notification becomes a multi-year project.

What TTUHSC Patients Should Do Right Now

  • Assume your data is compromised. If you received care at TTUHSC's Lubbock or El Paso campuses any time before September 2024, your records may have been in the stolen files. Don't wait for a notification letter: those took 19 months.
  • Freeze your credit immediately. Contact Equifax (1-800-685-1111), Experian (1-888-397-3742), and TransUnion (1-888-909-8872). A credit freeze is free and prevents anyone from opening accounts in your name using your stolen SSN.
  • Enroll in the free credit monitoring. TTUHSC is offering 1-2 years of credit monitoring through IDX. Take it, but don't rely on it alone. Credit monitoring tells you after someone has already used your data. A freeze stops them before they can.
  • Monitor your insurance statements. Watch for Explanation of Benefits (EOB) letters for treatments you didn't receive. Medical identity fraud often shows up as unexpected charges or services listed on your insurance account.
  • Request your medical records. Get a copy of your current medical file from TTUHSC and review it for entries that aren't yours. Under HIPAA, you have a right to access your records. If you find discrepancies, report them immediately.
  • File an IRS Identity Protection PIN. With SSNs exposed, tax fraud is a real risk. Visit irs.gov to get an IP PIN that prevents fraudulent tax returns filed in your name.

Healthcare Breaches Are Getting Worse, Not Better

TTUHSC isn't an outlier. It's the pattern.

Healthcare is the most-breached industry in the United States, and it's not close. Medical records sell for up to $1,000 each on dark web markets (ten times the value of a credit card number) because they contain enough personal information to commit multiple types of fraud simultaneously [5].

The Change Healthcare breach in February 2024 affected 100 million Americans. The Ascension Health breach in May 2024 disrupted hospitals across 19 states. And TTUHSC adds another 1.46 million patients to the growing list of people whose most intimate health data is now permanently available to anyone who wants it.

The common thread: attackers got in through a vendor or third-party connection, spent days or weeks inside the network undetected, and exfiltrated massive amounts of data before anyone stopped them. Real-time monitoring isn't keeping up. Breach notification laws aren't keeping up. The gap between when your data is stolen and when you find out keeps getting wider.

Nineteen months. That's how long TTUHSC patients waited. The data was on the dark web for seventeen of those months. The only thing the notification letter changes is that now you officially know what criminals have known about you since October 2024.

Sources

  1. GovTech: "Tech Health Sciences Center Cyber Attack Impacted 1.4M Patients" (2026)
  2. Infosecurity Magazine: "Texas Tech University Data Breach Impacts 1.4 Million" (2026)
  3. SecurityWeek: "Texas Tech University Data Breach Impacts 1.4 Million People" (2026)
  4. The Daily Hodl: "Texas University Discloses Colossal Data Breach: 813,892 People Exposed" (April 28, 2026)
  5. HIPAA Journal: "Texas Tech University Health Sciences Center Ransomware Attack Affects 1.46 Million Patients" (2026)