# Cardiology Associates of Port Huron (Port Huron Heart Center) Breached by Orova Ransomware Group — 144.00 GB of Patient Data Exfiltrated

> Cardiology Associates of Port Huron, P.C. (porthuronheartcenter.com), a Michigan-based cardiovascular practice operating since 1974, was breached by the Orova ransomware group. Over 144.00 GB of patient data (244,215 files) was exfiltrated during a June 2026 intrusion, with Orova posting an extortion notice on their Tor-hosted leak site on July 10, 2026, threatening public release of the stolen data unless a company representative initiated negotiations. As of August 6, 2026, the practice has not publicly disclosed or confirmed the incident, placing them at risk of HIPAA breach notification penalties.

- **Published:** 2026-08-06T00:00:00Z
- **Last reviewed:** 2026-08-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1916
- **ID:** TL-2026-1916
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Actor:** Orova
- **Detections:** 9 · **IOCs:** 7 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On July 10, 2026, the Orova ransomware group added Cardiology Associates of Port Huron, P.C. (d/b/a Port Huron Heart Center) to their Tor-hosted data leak site, claiming responsibility for an intrusion that resulted in the theft of 144.00 GB of data (244,215 files). The group posted the extortion notice with the statement: "The full leak will be published soon, unless a company representative contacts us via the channels provided," indicating that negotiations had not yet begun as of the posting date.

Cardiology Associates of Port Huron is a physician-owned partnership founded in 1974, headquartered at 1222 10th Avenue, Port Huron, Michigan. The practice employs 3 interventional cardiologists, a vascular interventionist, an electrophysiologist, and 3 non-invasive cardiologists supported by nurse practitioners, physician assistants, registered nurses, and exercise physiologists. It operates 7 satellite clinics spanning north into Michigan's Thumb region and south to Algonac.

Orova is an emerging ransomware group first observed in May 2026, classified by WatchGuard Technologies as a "Data Broker" operation employing double-extortion tactics (data theft plus encryption), with an additional tactic of "free data leaks" — publicly releasing stolen data without payment as a coercive measure. The group has claimed 24+ victims across 6 countries (United States — 13 victims, Hong Kong — 5, Taiwan — 4, with single victims in Brazil, Egypt, and Japan), targeting diverse sectors including healthcare (4 confirmed victims — the most-hit sector), manufacturing, finance, IT, insurance, and construction.

Orova's observed attack chain includes: purchasing compromised credentials from infostealer markets (~24% of victims had domain credentials detectable in infostealer markets prior to attack per Hudson Rock/ransomware.live data), exploiting unpatched vulnerabilities in public-facing applications, deploying spear-phishing campaigns, conducting internal reconnaissance and Active Directory profiling, exfiltrating sensitive data before encryption, identifying and destroying/corrupting backups to eliminate recovery options, and deploying mass encryption across file servers, domain controllers, email servers, and operational systems.

The group operates a sophisticated extortion infrastructure including a Tor-hosted leak site (mll5ddmdzgiq2siv3qnocmmqyiigfpajtc663xtf32qtp6weycyx2hyd.onion), a separate Tor-hosted negotiation/chat portal (ns7y6bxawualjj5rpo5num6syejd7hgaowrndk3r4duxu2iyinzv6hid.onion), and a Tox encrypted messaging ID for direct victim communication. Data exfiltration volumes documented across victims range from 15.90 GB to 64.70 GB.

This breach exposes protected health information (PHI) from a cardiovascular practice, potentially including patient names, medical records, clinical histories, diagnoses, treatment plans, insurance information, Social Security numbers, billing data, and other personally identifiable information (PII). As a HIPAA-covered entity, Cardiology Associates is subject to mandatory breach notification requirements under HIPAA/HITECH, including notification to affected individuals, the HHS Office for Civil Rights (OCR), and potentially local media. The HHS OCR has intensified ransomware enforcement in 2026, issuing four settlements totaling $1,165,000 in April 2026 alone, and has now completed 20 ransomware-related enforcement actions.

No specific technical IOCs (malware hashes, C2 server IPs, encrypted file extensions, ransom note filenames) have been publicly released for Orova as of this report, as the group is too new for detailed reverse-engineering reports from major cybersecurity vendors. Monitoring of Orova's Tor infrastructure, continued victim tracking, and credential exposure assessments remain the primary detection vectors.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1190 Exploit Public-Facing Application
- T1566 Phishing
- T1204 User Execution
- T1685 Disable or Modify Tools
- T1003 OS Credential Dumping
- T1087 Account Discovery
- T1069 Permission Groups Discovery
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1021 Remote Services
- T1005 Data from Local System
- T1095 Non-Application Layer Protocol
- T1567 Exfiltration Over Web Service
- T1485 Data Destruction
- T1490 Inhibit System Recovery

## Sources

- [Cardiology Associates of Port Huron Remains Silent After Alleged Hack — DataBreaches.net](https://databreaches.net/2026/08/06/cardiology-associates-of-port-huron-remains-silent-although-they-were-allegedly-hacked-and-had-patient-data-stolen-in-june/)
- [OROVA Ransomware Attack on Cardiology Associates — DeXpose](https://www.dexpose.io/orova-ransomware-attack-on-cardiology-associates/)
- [Cardiology Associates of Port Huron Data Breach — BreachSense](https://www.breachsense.com/breaches/cardiology-associates-of-port-huron-data-breach/)
- [WatchGuard Ransomware Tracker — OROVA](https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/orova)
- [Orova Ransomware Breaches Five Hong Kong Firms — TechTimes](https://www.techtimes.com/articles/323271/20260806/orova-ransomware-breaches-five-hong-kong-firms-sfcs-first-cyber-fine-lands-same-day.htm)
- [ransomware.live — Orova Tracking Page](https://www.ransomware.live/)
- [HHS OCR Settles Four HIPAA Security Rule Ransomware Investigations — HHS.gov](https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html)
- [FalconFeeds.io — Orova Bulk Alert (24 Victims)](https://falconfeeds.io/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1916
