At a glance
- HCRG Care Group confirmed it was investigating a cyber incident in February 2025 after a ransomware group claimed to have accessed sensitive data
- Some patients were reportedly notified in June 2026 that their personal data may have been compromised.
- If your personal data was affected, you may be able to claim for financial loss, distress or both
- You should keep any notification letter, monitor your accounts and record any suspicious activity
- The ICO can investigate data protection concerns, but it can’t award compensation.
- You don’t always need to have lost money to bring a data breach claim, but you’ll need to show the breach affected you in a real way
If you’ve received a letter about the HCRG Care Group cyber attack, you’re probably wondering what’s happened, what information may have been exposed and what you should do now.
That’s completely understandable.
Healthcare data is personal. It can include details about your identity, treatment, appointments or medical history. When that kind of information is involved in a breach, it can feel intrusive and unsettling, even if you haven’t lost any money.
This guide explains what’s known so far, what steps you can take and how a data breach compensation claim may work if your information was compromised.
What happened in the HCRG Care Group cyber attack?
HCRG Care Group confirmed in February 2025 that it was investigating a cybersecurity incident after a ransomware group claimed it had accessed data from the organisation’s systems.
The incident has been publicly linked to the Medusa ransomware group.
Reports in June 2026 said some patients had started receiving notification letters about the HCRG Care Group data breach. According to reporting by DataBreaches.net, one notification referred to personal information including a date of birth, address, National Insurance number, phone number and hospital number.
Not everyone affected will have had the same information exposed. Your own notification letter or email is the most important thing to check, as it should explain what HCRG Care Group believes may have happened to your data.
What is ransomware?
Ransomware is a type of cyber attack where criminals get into an organisation’s systems. They may lock files, steal data or threaten to publish information unless money is paid.
In a healthcare setting, this can feel especially worrying. The information held by health and care providers can be private, sensitive and difficult to replace, such as medical records, contact details and identity information.
Why healthcare data is sensitive
Health information is classed as special category data under UK data protection law. This means it needs stronger protection because of the harm that could be caused if it’s misused or exposed.
For those affected, a healthcare data breach can have consequences that go well beyond inconvenience.
It may cause anxiety, embarrassment, loss of privacy or worry about what could happen later. For some people, the hardest part is not knowing who has seen their information or whether it could be used for fraud, scams or identity misuse.
How can you find out whether your information was affected?
The clearest sign is receiving a notification letter or email from HCRG Care Group.
If you’ve had one, read it carefully and check:
- What information may have been involved
- When the incident happened
- Whether any protective steps have been recommended
- Whether you’ve been given a reference number
- How to contact HCRG Care Group with questions
Keep the notification safe. Don’t delete the email or throw the letter away, even if you don’t feel affected right now.
If you haven’t received a notification but you’re worried, you may be able to contact HCRG Care Group and ask whether your information was involved.
You can also make a subject access request. This is a formal request asking an organisation for copies of the personal information it holds about you. It can help you understand what data was stored and how it may have been used.
What should you do if you receive an HCRG Care Group notification?
Try not to panic. There are practical steps you can take straight away.
You should:
- Keep the letter or email safe
- Save screenshots or copies of any online messages
- Check what type of data was affected
- Monitor your bank accounts for unusual activity
- Watch out for phishing emails, scam calls and suspicious texts
- Change reused passwords, especially for email, healthcare or financial accounts
- Check your credit file if identity details were involved
- Keep a note of any stress, anxiety or disruption caused by the breach
Phishing is when scammers pretend to be a trusted organisation to trick you into giving away information, making a payment or clicking a harmful link.
After a healthcare data breach, be careful with unexpected messages about appointments, medical records, payments, identity checks or password resets. If something feels off, don’t click the link. Go directly to the organisation’s official website or contact them using details you already trust.
Can you claim compensation after the HCRG Care Group cyber attack?
You may be able to make an HCRG Care Group compensation claim if your personal data was compromised and you suffered harm because of it.
A UK GDPR data breach claim can include:
- Material damage: financial loss, like money stolen through fraud or costs linked to protecting your identity.
- Non-material damage: emotional harm, like distress, anxiety, loss of sleep or loss of privacy.
You don’t always need to have lost money to bring a claim.
However, you’ll usually need to show that the breach affected you in a real way. That could mean distress about private medical information being exposed, time spent dealing with suspicious activity, worry about identity misuse or actual financial loss.
The success of a data breach claim depends on its own facts. The type of data involved, how it was exposed and how it affected you will all matter.
What evidence could help support a claim?
Evidence helps show what happened and how the breach affected you.
Useful evidence may include:
- Your HCRG Care Group notification letter or email
- Any emails or text messages about the breach
- Screenshots of suspicious messages
- Bank statements showing unusual activity
- Credit report alerts
- Fraud reports
- Correspondence with your bank
- Medical notes if the breach affected your mental health
- Notes about anxiety, sleep problems or disruption
- Any response from HCRG Care Group to questions you’ve asked
You don’t need to have everything before asking for advice.
Express Solicitors can look at what you already have, explain what may be useful and tell you whether more information is needed.
Do you need to complain to the ICO before making a claim?
Not always. The Information Commissioner’s Office is the UK regulator for data protection. It can look at whether an organisation has handled personal data properly. However, it does not award compensation. An ICO complaint may still be useful if:
- HCRG Care Group hasn’t responded to you
- The response doesn’t answer your concerns
- You want the regulator to review how your data was handled
- Express Solicitors advises that an ICO complaint could support your case
Myth vs fact: HCRG Care Group data breach claims
| Myth | Fact |
| I can only claim if money was stolen. | You may be able to claim for distress as well as financial loss. |
| The ICO will award me compensation. | The ICO can investigate concerns, but it cannot award compensation. |
| Everyone affected will automatically receive compensation. | Eligibility depends on your circumstances and evidence. |
| I should throw the letter away if I feel fine now. | Keep it safe, as it may be important evidence later. |
| A cyber attack means the organisation is always legally liable. | A claim depends on whether data protection law was breached and whether harm was caused. |
How to start a HCRG Care Group compensation claim
A claim usually begins with a review of your own circumstances.
We will look at:
- Whether you received a notification
- What type of data may have been affected
- How the breach has affected you
- Whether you’ve lost money
- Whether you’ve experienced distress, anxiety or loss of privacy
- What evidence is available
- Whether data protection law may have been breached
- What steps should be taken next
If your claim can proceed, we can contact HCRG Care Group or its representatives, gather evidence and negotiate compensation where appropriate.
You may be able to make a claim under a no win, no fee agreement (also called a conditional fee agreement). This means you don’t pay your solicitor’s fees if your claim is unsuccessful, subject to the terms of the agreement.
If your claim succeeds, a success fee is deducted from your compensation. We’ll explain this clearly before you decide whether to go ahead.
Start a claim with Express Solicitors
The HCRG Care Group cyber attack has raised understandable concerns for patients, employees and others whose personal information may have been affected.
If you’ve received a notification, keep it safe, check what information was involved and take steps to protect yourself from scams or identity misuse. If the breach has caused financial loss, distress or another impact, you may be able to bring a healthcare data breach compensation claim.
If you believe your personal information may have been compromised in the HCRG Care Group cyber attack, contact Express Solicitors for a free assessment to find out whether you may be eligible to make a data breach compensation claim.
HCRG Care Group cyber attack FAQs
What happened in the HCRG Care Group cyber attack?
HCRG Care Group confirmed in February 2025 that it was investigating a cybersecurity incident after a ransomware group claimed it had accessed sensitive data. The incident has been publicly linked to Medusa ransomware.
Can I claim compensation after the HCRG Care Group data breach?
You may be able to claim if your personal data was compromised and the breach caused financial loss, distress or another recognised impact. Eligibility depends on your individual circumstances and the evidence available.
What evidence do I need to make a claim?
Your notification letter is likely to be important. You should also keep emails, screenshots, suspicious messages, bank records, credit alerts and notes about how the breach has affected your wellbeing.
Can I claim if I have not lost any money?
Possibly. Data breach compensation can include non-material damage, such as distress, as well as material damage, such as financial loss.
Do I need to report the breach to the ICO?
You do not always need to complain to the ICO before seeking legal advice. The ICO can investigate data protection concerns, but it cannot award compensation.
How long do I have to make a data breach claim?
Time limits can apply to UK GDPR data breach claims. The exact deadline can depend on the facts of your case, so it is sensible to seek legal advice as soon as possible.
What should I do if I receive a notification letter from HCRG Care Group?
Keep the letter safe, check what information was affected, monitor your accounts and stay alert to suspicious messages. You should also record any distress, disruption or financial loss linked to the breach.

