Oklahoma Healthcare Giant Integris Health Suffers Devastating Data Breach: 2.4 Million Patient Records Compromised

Photo of Brian Largent

Brian Largent

CEO, ArcLight Group

October 9, 2025 9 min read
Share:
Integris Security Breach

Oklahoma City, OK – Integris Health, Oklahoma’s largest not-for-profit healthcare system, confirmed a massive data breach affecting approximately 2.4 million patients following a cyberattack that began on November 28, 2023. The incident serves as a stark warning for Oklahoma healthcare organizations and small businesses about the catastrophic consequences of inadequate cybersecurity, and about the hard operational lessons every Oklahoma practice should take from it.

At The ArcLight Group, healthcare has been a core focus of our practice since 2008. We work with Oklahoma medical groups, clinics, and specialty practices every day, and the Integris breach is exactly the kind of event we spend our careers trying to prevent. What follows is a breakdown of what happened, why healthcare keeps getting hit, and what Oklahoma practices should be doing differently right now.

The Attack Timeline and Impact

The threat actor gained unauthorized access to Integris Health’s IT systems on November 28, 2023, successfully exfiltrating sensitive patient data without encrypting files, allowing the healthcare provider to continue operations while data was stolen. Integris Health did not notify affected patients until December 24, 2023, nearly a month after the initial breach, when cybercriminals began directly contacting victims via email.

The compromised information included patient names, dates of birth, contact information, demographic data, and Social Security numbers. The threat actor told media outlets they were selling data for 2.3 million Integris patients on dark web marketplaces.

Direct Patient Extortion Tactics

After Integris Health refused to pay the ransom demand, cybercriminals adopted aggressive tactics by directly extorting patients. Victims received emails offering two options: pay $3 to view their stolen data or pay $50 to have it deleted, with threats that failure to pay by January 5, 2024, would result in their information being sold to data brokers.

The hackers’ communications included accurate personal details (dates of birth, Social Security numbers, addresses, phone numbers, insurance information, and employment details) as proof they possessed legitimate stolen data. This is a tactic ransomware operators have increasingly turned to as a pressure lever, and it’s exactly as professional as it sounds. These aren’t kids in hoodies. They’re organizations with call centers, customer service reps, and negotiation teams.

Why Healthcare Keeps Getting Hit: A Practitioner’s View

Healthcare is one of ArcLight Group’s biggest focus areas, and I’ve watched this pattern get worse for the better part of two decades. Hospitals and clinics check every box a ransomware operator looks for when picking a target.

The math works in the attacker’s favor. A manufacturing plant that loses its network might lose production for a week and eat the cost. A hospital or large practice that loses its network is diverting patients, canceling procedures, and watching revenue evaporate at a staggering rate. When you’re bleeding that kind of money every single day, even a seven-figure ransom starts to look like the cheaper option. That urgency is the product. That’s what ransomware operators are selling back to you.

Layer on top of that the regulatory pressure of HIPAA, the lifetime value of patient records on the dark web, and the fact that many Oklahoma practices run on aging infrastructure that’s been patched together over years, and it becomes clear why healthcare is the industry attackers keep returning to. For a deeper breakdown of this dynamic, see our companion piece on the lessons from a hospital ransomware attack, which walks through the pattern we’ve seen repeatedly in public incidents including the widely-reported Stillwater Regional Medical Center attack.

Legal Fallout and Regulatory Concerns

Multiple class-action lawsuits were filed against Integris Health, alleging the organization failed to implement reasonable and appropriate security measures to protect patient data despite being aware of high ransomware risks facing hospitals. Attorneys representing affected patients criticized Integris Health for lack of transparency and failure to communicate effectively, with one describing the response as “corporate amnesia.”

According to breach notifications, Integris Health did not offer identity theft protection or credit monitoring services to affected individuals, essentially leaving victims to manage the lifetime threat of identity fraud at their own expense. For Oklahoma practices, this is a preview of what regulators and plaintiffs’ attorneys will be looking for going forward: Did you maintain reasonable security controls? Did you notify patients promptly? Did you offer remediation?

Oklahoma’s Growing Cybersecurity Crisis

Oklahoma’s healthcare sector has become a prime target for cybercriminals. Integris Health’s breach exposed data from almost 2.4 million patients, while hospitals throughout the state continue facing persistent cyber threats. The threat extends beyond healthcare. The University of Oklahoma discovered unusual cyber activity on its network, with a ransomware gang claiming to have stolen 91 GB of data including employee information and financial records. These incidents demonstrate that no Oklahoma organization, regardless of size or sector, is immune.

Critical Security Gaps the Breach Exposed

The Integris Health breach revealed several fundamental failures that we see repeatedly in healthcare IT environments:

  • Inadequate Network Monitoring: The initial breach went undetected for weeks, allowing attackers extended access to sensitive systems.
  • Insufficient Endpoint Protection: Threat actors successfully exfiltrated massive volumes of data without triggering security alerts.
  • Lack of Multi-Factor Authentication (MFA): Credential-based access remains the most common entry point for attackers targeting healthcare.
  • Delayed Incident Response: Nearly one month elapsed before affected patients received notification.
  • Absence of Proactive Threat Detection: No SIEM or managed detection solution flagged the activity in real time.

What Oklahoma Healthcare Practices Should Learn

If you’re running a medical practice, clinic, or specialty group in Oklahoma, the Integris breach should push five specific items to the top of your list this quarter.

1. Audit your backup architecture. Not whether you have backups, but whether they’d survive a real attack. If your backup server is reachable over the same network with the same admin credentials, it’s gone the moment the attackers own your domain. Real backup protection means three things: separate network, separate authentication, separate encryption. If any one of those is shared with your production environment, you have a vulnerability.

I’ll give you a real example. A Tulsa-based asphalt company had offsite backups, which is smart. Except they used the same admin password for the offsite backup system as they used for everything else. The attackers enumerated credentials, found the backup account, destroyed the backups, and then kicked off encryption. By the time anyone noticed, the safety net was already gone. Password reuse on backups is one of the most common and most fatal mistakes I see in healthcare environments too.

2. Put MFA on every remote access point. VPN, RDP, email, cloud admin consoles, EHR portals. Every remote surface that relies on a password alone is a door waiting to be opened.

3. Replace traditional antivirus with EDR or MDR. Definition-based antivirus was built for a different era. Modern endpoint detection and response tools use behavioral analytics and AI to catch attacks that have never been seen before. In healthcare, where a single compromised workstation can cascade into an EHR outage, this is no longer optional.

4. Segment your network. Clinical systems, administrative systems, medical IoT devices, and guest Wi-Fi should not all share one flat network. Segmentation limits blast radius, and in healthcare it can be the difference between a contained incident and a full operational shutdown.

5. Get an outside assessment before an incident. Internal IT teams are too close to their own environment to see the gaps. A third-party risk assessment is one of the highest-ROI investments a healthcare organization can make, and it’s the kind of documentation that matters enormously when regulators and insurers come asking.

The Insurance Reality After a Breach

Most healthcare organizations carry cyber insurance, and they should. But I want practice owners to understand what actually happens after you file a claim. The insurance company will investigate whether the incident was your fault. If they can demonstrate that you failed to maintain reasonable security controls (missed patches, weak passwords, no MFA on remote access), they will use that to reduce or deny your claim.

Even if they pay, the aftermath is brutal. After a major ransomware claim, premiums don’t just tick up. I’ve seen organizations hit with 10 to 30 times their previous premium at renewal. Some carriers drop you entirely, and finding replacement coverage with a ransomware incident on your record is incredibly difficult and expensive. The insurance that was supposed to protect you ends up being a one-time parachute with a massive back-end cost.

For a deeper look at how a ransomware event plays out from the inside, including the call-center-style negotiation process and the months-long rebuild that follows, see What Really Happens When Your Business Gets Ransomware.

The Long Tail Nobody Talks About

Here’s what the news coverage of Integris won’t tell you. Even after a healthcare organization pays for decryption keys or restores from backups, they are not done. Not even close. The infrastructure gets rebuilt over months, sometimes years. Shadow infrastructure accumulates. Systems that were “temporarily” stood up during the crisis become permanent because nobody has time to do it right. I’ve seen organizations still dealing with aftereffects three, four, five years after the attack. Legacy configurations nobody fully understands. Compliance gaps that crept in during the rebuild. The ransomware attack isn’t an event. It’s a before-and-after line in the life of your organization.

How The ArcLight Group Helps Oklahoma Healthcare Clients

At The ArcLight Group in Tulsa, healthcare security isn’t a side practice. It’s a core focus we’ve built around HIPAA requirements and the operational reality of keeping a medical practice running while maintaining real security. Our approach is layered and boring on purpose.

  • 24/7 Monitoring and Managed Detection: continuous visibility across endpoints, servers, and cloud, so exfiltration doesn’t go undetected for weeks the way it did at Integris.
  • Endpoint Detection and Response (EDR/MDR): behavioral protection across every workstation and server, replacing outdated definition-based antivirus.
  • Enforced Multi-Factor Authentication: applied across EHR, email, VPN, and cloud admin consoles.
  • Backup Architecture Done Right: separate network, separate authentication, separate encryption, and regular restore testing so you know the backups actually work.
  • Security Awareness Training: recurring micro-trainings and simulated phishing, because email remains the dominant entry point.
  • HIPAA and Compliance Support: documentation, policies, and controls aligned with HIPAA, and readiness for Oklahoma’s strengthened breach notification requirements taking effect January 1, 2026.
  • Incident Response Planning: a real plan, tested, so that if something does slip through, you’re not making triage decisions from scratch in the middle of the worst day of your career.

Don’t Be the Next Headline

The question isn’t whether your Oklahoma practice will face a cyber threat. It’s when, and whether you’ll be ready. Integris Health is the largest Oklahoma healthcare breach on record, but it won’t be the last. The practices that come through these events intact are the ones that invested in layered defenses and backup architecture before the phone call.

If you want a clear-eyed look at where your practice actually stands, ArcLight offers a free 27-point IT Risk and Ransomware Assessment for Oklahoma healthcare organizations. No hard sell. Just a straight answer on where your gaps are and what to prioritize first.

Call The ArcLight Group at (918) 270-6600 or reach out through our website to schedule your complimentary assessment. We serve Tulsa, Oklahoma City, Broken Arrow, Bartlesville, and surrounding communities.


Brian Largent is the CEO and founder of The ArcLight Group, a Tulsa-based managed IT and cybersecurity firm serving Oklahoma businesses since 2008, with a long-standing focus on healthcare. ArcLight provides 24/7 monitoring, managed detection and response, HIPAA compliance support, and incident response planning to medical practices and organizations across Oklahoma.

Photo of Brian Largent
About the Author

Brian Largent

Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)

Ready to harden your environment?

Get the 27-point assessment we run on every new client

Two hours. One real engineer. A written report telling you exactly where your gaps are — whether or not you ever hire us.

No hard sell. No obligation. Month-to-month after — cancel anytime.