How to make a claim after the HCRG Care Group cyber attack
How to make a claim after the HCRG Care Group cyber attack
At a glance
- HCRG Care Group investigated a cyber security incident in February 2025 after a ransomware group claimed to have accessed data from its systems.
- Some patients were reportedly notified in June 2026 that their personal information may have been affected.
- A cyber attack doesn’t automatically make HCRG Care Group legally liable for compensation.
- You may have a claim if data protection law was breached and you suffered financial loss, distress or another recognised form of damage.
- Keep your notification, monitor your accounts and record any suspicious activity or emotional impact.
- The Information Commissioner’s Office can investigate data protection concerns but can’t award compensation.
Receiving a letter saying that your personal information may have been caught up in a cyber attack can leave you with more questions than answers.
You might want to know exactly what information was involved, whether anybody has used it and what you can do to protect yourself. When the data relates to your health, identity or finances, simply knowing that an unauthorised person may have accessed it can feel deeply intrusive.
There are practical steps you can take now. You may also be able to claim compensation if HCRG Care Group failed to meet its data protection duties and the incident caused you genuine harm.
This guide explains what’s currently known about the HCRG Care Group cyber attack, what to do after receiving a notification and how a data breach claim works.

What happened in the HCRG Care Group cyber attack?
HCRG Care Group confirmed in February 2025 that it was investigating a cyber security incident after a ransomware group claimed to have accessed information held within its systems.
The incident was publicly linked to the Medusa ransomware group.
High Court records later referred to unidentified individuals allegedly obtaining data from HCRG Care Group’s systems between approximately 26th January and 12th February 2025. The court granted an injunction intended to prevent the information from being disclosed, used or published further.
Reports published in June 2026 indicated that some patients had begun receiving notification letters more than a year after the incident. Some reported notifications referred to data such as dates of birth, addresses, telephone numbers, National Insurance numbers and hospital numbers.
The information involved won’t necessarily be the same for everyone. Your individual notification should explain which categories of personal data HCRG Care Group believes may have been affected.
What is ransomware?
Ransomware is a type of cyber attack in which criminals gain unauthorised access to an organisation’s computer systems.
They may:
- Lock or encrypt files
- Copy confidential information
- Disrupt access to systems
- Demand money to restore access
- Threaten to publish stolen data
Paying a ransom doesn’t guarantee that the information will be returned, deleted or left unused.
Healthcare organisations can be attractive targets because they hold large volumes of sensitive information about patients, employees and service users.
Why healthcare data needs extra protection
Medical information can reveal some of the most private details about your life.
It can include your diagnoses, medication, treatment history, appointments and contact with particular healthcare services.
Health information is treated as special category data under UK data protection law. Organisations processing it must meet additional legal requirements because of its sensitive nature.
If this type of information is exposed, you might experience:
- Anxiety about who has seen it
- Embarrassment or a loss of privacy
- Concern about fraud or identity theft
- Fear that confidential medical information could be published
- Reduced trust in organisations holding your data
- Worry about how the information could be used in future
You don’t necessarily have to suffer financial loss to pursue compensation. However, you’ll normally need to show that a breach of data protection law caused genuine material or non-material damage. The ICO confirms that recoverable damage can include both financial loss and distress.
How can you find out whether your information was affected?
Receiving a notification from HCRG Care Group is the clearest indication that the organisation believes your data may have been involved.
Read the notification carefully. It may explain:
- Which personal information was affected
- When the incident took place
- What HCRG Care Group has discovered
- Whether it recommends any protective action
- Who to contact with questions
- Whether your case has a reference number
Keep the original letter or email, even if you haven’t noticed any immediate consequences.
If you haven’t received a notification but believe your information could have been involved, contact HCRG Care Group and ask it to clarify the position.
You can also make a subject access request to obtain copies of the personal information the organisation holds about you. However, a subject access request won’t necessarily establish whether criminals accessed or copied that data during the incident.
What should you do if you receive an HCRG Care Group notification?
If you receive a notification, there are several practical steps you can take. You should:
- Keep the letter or email safely
- Save screenshots of any related online messages
- Check which categories of personal information may have been affected
- Monitor your bank accounts for unusual transactions
- Remain alert to phishing emails, scam telephone calls and suspicious text messages
- Change passwords that you use across multiple accounts, particularly for email and online banking
- Check your credit report if identity information was involved
- Keep a record of any distress, inconvenience or financial loss connected to the breach
Be aware of phishing scams
Following a cyber attack, criminals sometimes use stolen information to make fraudulent emails or messages appear more convincing.
You should be particularly cautious if you receive unexpected communications relating to appointments, medical records, payments or password resets.
Rather than clicking links in unsolicited messages, visit the organisation’s official website or contact it using details you already know are genuine.
Who can make a claim after the HCRG Care Group cyber attack?
If your personal information was compromised and the breach caused you harm, you may be entitled to claim compensation. Under UK data protection law, compensation may include:
Material damage
Material damage relates to financial losses, such as:
- Money lost through fraud
- Costs associated with protecting your identity
- Expenses resulting from misuse of your personal information
Non-material damage
Non-material damage relates to the emotional impact of a breach, including:
- Distress
- Anxiety
- Sleep disturbance
- Loss of privacy
- Psychological harm
It’s important to remember that financial loss isn’t essential in every case.
However, you will need to demonstrate that the breach had a genuine impact on you. This might include distress caused by the exposure of private medical information, time spent dealing with fraud risks or actual financial losses.
Every claim is assessed on its own facts.

What evidence could help support your claim?
Evidence helps demonstrate both what happened and how the breach affected you. Helpful evidence may include:
- Your HCRG Care Group notification letter or email
- Emails or text messages relating to the breach
- Screenshots of suspicious communications
- Bank statements showing unusual activity
- Credit monitoring alerts
- Fraud reports
- Correspondence with your bank
- Medical records where appropriate
- Notes explaining how the breach affected your wellbeing or daily life
- Any responses received from HCRG Care Group
You don’t need to have every piece of evidence before seeking legal advice. Our solicitors can advise which documents are likely to be most useful and whether any additional evidence may be needed.
Do you need to complain to the ICO before making a claim?
Not necessarily. The Information Commissioner’s Office regulates data protection law in the UK and can investigate concerns about how organisations handle personal information.
However, the ICO doesn’t award compensation. An ICO complaint may still be appropriate if:
- HCRG Care Group hasn’t responded to your concerns
- You believe its response is incomplete
- You would like the regulator to investigate how your information was handled
- Your solicitor advises that an ICO investigation may assist your case
How to make a claim after the HCRG Care Group cyber attack
If you believe you have been affected, the claims process will begin with reviewing your individual circumstances. This involves considering:
- Whether you received a notification
- What information may have been exposed
- Whether you have experienced financial loss
- Whether the breach caused distress or another form of harm
- What supporting evidence is available
- Whether there appears to have been a breach of data protection law
If you decide to instruct our solicitors, they can assess the available evidence, advise whether you may have grounds for a claim and, where appropriate, contact HCRG Care Group or its representatives on your behalf.
We handle data breach claims through a no win, no fee agreement, also known as a Conditional Fee Agreement. Under this arrangement, you won’t pay your solicitor’s legal fees if your claim is unsuccessful, subject to the terms of the agreement.
If your claim succeeds, a success fee may be deducted from your compensation. Our solicitors will explain the funding arrangement fully before you decide whether to proceed.
Getting advice about the HCRG Care Group cyber attack
The HCRG Care Group cyber attack has understandably raised concerns for patients and others whose personal information may have been affected.
If you have received a notification, keep it safe, review the information it contains and take sensible steps to protect yourself against fraud or identity misuse.
If the incident has caused financial loss, emotional distress or another recognised form of harm, you may wish to seek legal advice about whether you could make a data breach compensation claim.
At HNK Solicitors, we can advise you on your circumstances, explain the claims process and help you understand whether you may have grounds to pursue compensation. Get in touch to begin.
Frequently asked questions
What happened in the HCRG Care Group cyber attack?
HCRG Care Group confirmed in February 2025 that it was investigating a cyber security incident after a ransomware group claimed to have accessed data from its systems. The incident has been publicly linked to the Medusa ransomware group.
Can I claim compensation after the HCRG Care Group data breach?
You may be able to claim if your personal information was compromised and the breach caused financial loss, emotional distress or another recognised form of harm. Whether you are eligible will depend on the facts of your case.
Can I make a claim if I have not lost any money?
Possibly. Compensation may be available for non-material damage, including distress or psychological harm, as well as financial losses.
What evidence should I keep?
You should retain your notification letter, relevant emails, screenshots, bank statements, fraud reports, credit alerts and any records showing how the breach has affected you.
Do I need to complain to the ICO first?
Not in every case. The ICO can investigate concerns about data protection but cannot award compensation.
Is there a time limit for making a claim?
Yes. Time limits apply to data breach claims, although the deadline will depend on the circumstances of your case. Seeking legal advice promptly is usually advisable.
What should I do if I receive a notification from HCRG Care Group?
Read it carefully, keep it safe, monitor your accounts, stay alert to scams and keep records of any financial or emotional impact the breach has had on you.