Praxis EMR Data Breach Lawsuit: A Ransomware Claim, Not Yet a Case
Questions about this case?
AI Legal Assistant · free · answers in seconds · general information, not legal advice
Praxis EMR is a cloud-based electronic health record used by doctors' offices, mostly small primary-care practices. On October 5, 2026, a ransomware group called Insomnia listed it as a victim. As of October 11, 2026, Praxis EMR has not publicly confirmed a breach, nobody has said what data or how many patients are involved, and we found no Praxis EMR data breach lawsuit on file. There is no settlement and no claim form.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Has Actually Been Reported
Praxis EMR is developed by Infor*Med Medical Information Systems Inc., a California company. Its own filing describes the software as “used mostly as a cloud model in small and medium size practices,” mostly in primary care. That matters: if the vendor's systems were reached, the records at risk would belong to patients of many unrelated practices.
What exists so far is a claim by the attackers, not a confirmed incident. Dark-web monitoring site Ransomware.live recorded the Insomnia group's posting about Praxis EMR on October 5, 2026, with an estimated attack date of September 17, 2026. Breachsense logged the same claim on October 6, 2026 and lists the leak size as “Unknown.” Ransomware groups post victim names to pressure them into paying; a listing is not proof that patient records were taken.
Case Details
No lawsuit found. A search of federal dockets on CourtListener for “Praxis EMR” on October 11, 2026 returned only older, unrelated patent and antitrust matters — no data breach complaint. State-court filings are not searchable the same way, so a new state case cannot be fully ruled out. A lawyer-advertising site posted on October 6, 2026 that attorneys are “looking into whether a class action lawsuit can be filed” — that is recruitment for a possible case, not a filed one. If a complaint is filed, this page will list the court, case number and date.
Status: Unconfirmed Breach, No Lawsuit, No Settlement
Could Your Records Be Involved?
Only if your doctor's office uses Praxis EMR — and even then, nothing is confirmed yet. You were almost certainly never a Praxis EMR customer yourself; your practice was. Many patients do not know which record system their doctor uses, so the honest answer for most people today is “unknown.”
The practical test is your mail. If a breach is confirmed, notices usually go to patients, and they may come from your doctor's practice rather than from the vendor. California, for example, requires a sample copy to be filed with the Attorney General when a notice goes to more than 500 California residents, and it notes that the organization sending the notice is not always the one that was breached. Keep any letter you receive: it states which of your data fields were involved.
Is There Any Money?
Praxis EMR Breach Claim Timeline
- 1
September 17, 2026 — Estimated Attack Date
Ransomware.live estimates the attack on Praxis EMR occurred around this date. It is an estimate by a monitoring site, not a date confirmed by the company.
- 2
October 5, 2026 — Insomnia Lists Praxis EMR
The ransomware group Insomnia names Praxis EMR as a victim; Ransomware.live records the posting the same day.
- 3
October 6, 2026 — Monitoring Sites and Lawyers React
Breachsense logs the claim with leak size “Unknown.” A lawyer-advertising site starts recruiting people for a possible class action.
- 4
October 11, 2026 — Still Unconfirmed
No company statement, no count of affected patients, no list of exposed data and no lawsuit found.
- 5
Next — What Would Change the Picture
A confirmed incident would bring notice letters, a regulator filing with a headcount and, usually, the first complaints. Each will be dated here when it exists.
Three Things to Watch For
An unconfirmed breach with no official information is an easy cover story:
“Claim your Praxis EMR settlement” pages
There is no settlement and no claims portal. Any site asking for your Social Security number or bank details to “register” for a Praxis EMR payout is collecting data, not filing anything.
Calls or texts naming your doctor's office
Because Praxis EMR sits behind small practices, a scammer can name a local clinic and sound informed. A real breach notice comes by letter and does not ask you to read out your Social Security number or pay a fee. Call your practice back on the number you already have.
Messages claiming to hold your medical records
Ransomware claims are designed to frighten. An email saying your records were stolen and demanding payment to delete them should not be paid or answered — report it to your provider and to the FBI's IC3.
Praxis EMR Data Breach — Questions People Actually Ask
Is there a Praxis EMR data breach lawsuit?
Not that we could find as of October 11, 2026. A federal docket search showed no data breach case against Praxis EMR. Attorneys are advertising for people who may have been affected, which is a step before filing, not a lawsuit.
Was Praxis EMR actually hacked?
That is unconfirmed. The ransomware group Insomnia claims it attacked Praxis EMR, and monitoring sites recorded that claim on October 5 and October 6, 2026. Praxis EMR had not publicly confirmed or denied an incident when we checked.
What data was exposed in the Praxis EMR data breach?
Nobody has said. Breachsense lists the leak size as “Unknown,” and no notice letter or regulator filing describing the data has been published. An electronic health record can hold names, contact details, insurance and clinical information, which is why a confirmed breach would matter.
How many people were affected?
No number has been published. Healthcare breaches affecting many people normally appear on the HHS Office for Civil Rights breach portal with a headcount; we could not confirm such a filing for Praxis EMR as of October 11, 2026.
Who is Praxis EMR, and why would it have my information?
Praxis EMR is electronic health record software made by Infor*Med Medical Information Systems Inc. in California. Doctors' offices, mostly small primary-care practices, use it to keep patient charts in the cloud. If your doctor uses it, your chart lives in its system.
Is there a settlement or a claim form?
No. There is no settlement, no fund, no administrator, no claim form and no deadline. If that ever changes, class members are contacted by a court-appointed administrator.
Do I need to sign up somewhere to be included?
No. If a class action is ever filed and certified, class members are included automatically unless they opt out. Signing a lawyer's intake form is a separate choice, not registration for any payment.
What is worth doing right now?
Ask your doctor's office whether it uses Praxis EMR. Keep any breach letter you receive. A credit freeze at all three bureaus is free and reversible, and checking your insurer's explanation-of-benefits statements catches care billed in your name that you never received.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
Data Breach Settlement Calculator
Estimate what a resolved breach case typically pays per person
Open Class Action Settlements
Settlements with a claim form and a deadline you can still meet
Settlement Payout Calculator
How a settlement fund is split among class members
Aesto Health Data Breach
Another healthcare vendor breach reaching patients through providers