FQHC Ransomware Surge Q1 2026 — Sandhills (169K), Cherry Health (184K), Central Jersey Hit; Class-Action Lawsuits Now Routine
Comparitech's Q1 2026 healthcare ransomware roundup confirms 201 attacks (120 providers + 81 vendors) — three of which were FQHCs: Sandhills Medical Foundation (SC, 169,017 patients, INC Ransom group), Cherry Health (Michigan's largest FQHC, 184,000 patients), and Central Jersey Medical Center FQHC. Sandhills now faces a class-action investigation announced May 2026, signaling that civil litigation is becoming routine on top of OCR enforcement. Combined with OCR's April 23 four-entity ransomware sweep ($1.165M), the message to FQHC boards is unambiguous: Security Risk Analysis (45 CFR § 164.308(a)(1)(ii)(A)) is now the single most material ePHI compliance gap. CA FQHCs running OCHIN Epic, eClinicalWorks, NextGen, athenahealth — every IT environment with PHI — should refresh risk analysis before the Section 504 May 11 deadline lands and triggers heightened OCR scrutiny.
Key takeaways
- FQHC ransomware now triggers BOTH OCR enforcement AND civil class-action lawsuits — 2x exposure. Refresh Security Risk Analysis annually + document evidence at minimum
- Three FQHCs hit in Q1 2026 alone — pattern is mid-size FQHCs with limited dedicated cybersecurity. Visualutions, Huntress, KnowBe4 are FQHC-affordable cyber options worth evaluating
- BAA inventory + tested backup-restore procedures pair with risk analysis as the OCR-listed enforcement triad. Score yourself against the 4 settled entities (Apr 23, $1.165M) before OCR scores you
Primary source
Comparitech (Q1 2026 Healthcare Ransomware Roundup)FQHC Talent. (2026, May 6). FQHC Ransomware Surge Q1 2026 — Sandhills (169K), Cherry Health (184K), Central Jersey Hit; Class-Action Lawsuits Now Routine. Primary source: Comparitech (Q1 2026 Healthcare Ransomware Roundup). Retrieved May 12, 2026, from https://www.fqhctalent.com/intel/fqhc-ransomware-q1-2026-sandhills-cherry-central-jersey
More in Risk & Compliance
Jul 5
Section 1557 Language Access Annual Notice Year 1 Anniversary — July 5, 2026 Compliance Window
May 11
URGENT: HHS Section 504 WCAG 2.1 AA Digital Accessibility Deadline Hits FQHCs May 11, 2026 — 3 Weeks Away
May 7
MAJOR PIVOT — HHS OCR Extends Section 504 / WCAG 2.1AA Deadline by One Year to May 11, 2027
May 6
Salud Para La Gente (Santa Cruz/Monterey FQHC) Pays $750K to Settle False Claims Act Misbranded Contraceptives Case — First CA FQHC FCA Settlement of FY2026