When an independent family-medicine practice lands on a ransomware leak-site tracker, primary-care and small specialty practices feel the same pressure—email, the EHR and patient portal, billing, e-fax and scanning, and the vendor remote-access paths that keep a clinic day moving. Public aggregators indexed Raleigh Family Medicine as a claimed victim of the Booba Project ransomware group around October 2, 2026.
Ransomware.live lists discovery around 2026-10-02 12:51 UTC (attackdate ~2026-10-02 12:30 UTC; country US; activity Healthcare). The listed domain, rfppa.com, resolves to Raleigh Family Practice (HTTP 200 at publish research), which describes itself as an independently owned, provider-owned family practice in Raleigh, North Carolina, caring for adults and children since 1998. The tracker entry carries a short “Hospitals and Health Care” tag and an actor-stated data size—we treat those actor/tracker statements as unverified context, not confirmed facts about any incident. As of our sources, we have no confirmed practice disclosure of encryption, patient or employee data theft (including PHI), clinic downtime, or ransom payment—so we treat the Booba Project listing as a leak-site / tracker claim only.
For family-medicine, pediatric, internal-medicine, dental, and other small clinical practices across Georgia, Tennessee, Alabama, and New York, the useful lesson is identity hygiene plus tested EHR and office backups—not inventing a confirmed breach the named practice has not published.
What trackers report—and what they do not
Public facts from aggregators: Raleigh Family Medicine; Booba Project claim; discovery ~Oct. 2, 2026; U.S. healthcare listing tied to rfppa.com. Aggregators republish the actor listing; they do not equal a verified inventory of patient charts, insurance details, or staff records. We do not have a practice-confirmed encryption event, confirmed PHI exposure, an HHS breach-portal filing, operational downtime, or payment. Do not invent those details from silence—and do not treat a tracker “Healthcare” tag as proof that any specific data type was taken.
Small practices share a familiar pattern: Microsoft 365 or Google Workspace next to a hosted EHR, a patient portal, clearinghouse and billing logins, e-fax, and remote access for managed IT, the EHR vendor, and outside billing.
Why Brotherly-footprint practices should treat this as their drill
Patients still arrive at 7am whether or not a headline hits the inbox. Practices that lean on password-only email, untested backups, and shared front-desk logins inherit the headline as scam and continuity risk—even when your clinic is in Rome, Northwest Georgia, metro Atlanta, Chattanooga, Birmingham, Auburn/Opelika, or Wallkill, NY, and the claimed victim is a family practice in North Carolina.
Post-headline phishing is predictable: spoofed “EHR security update,” “patient portal reset,” “Booba claim,” or “insurance verification” messages, plus patient-facing texts asking for card numbers or portal passwords. Ask: if email or the EHR were degraded for a week, how would you still see today’s schedule, reach patients, process refills, and spot fake recovery calls?
Office moves and network refreshes are natural checkpoints—the practice’s own site announces a move later this month, an ordinary event when Wi-Fi, firewall rules, and backup jobs get rebuilt. Write a one-page continuity card—who to call, which system is authoritative, where the last known-good backup lives, how to run paper downtime—before the next tracker post arrives.
Clear takeaway
Treat the Booba Project leak-site claim against Raleigh Family Medicine as a continuity and scam-hygiene drill for independent primary-care and small clinical practices in Brotherly’s footprint—require MFA on email, EHR, patient-portal, billing, and admin logins; protect EHR exports, scanned documents, and shared drives with immutable copies and a restore test; inventory managed-IT, EHR, and billing-vendor remote access; retire shared front-desk accounts; rehearse paper downtime; and brief staff and patients against post-headline phishing—without inventing patient or employee data theft, encryption, downtime, or payment the practice has not confirmed.
Actions to take this week
- Require MFA on email (Microsoft 365 / Google Workspace), the EHR, patient portal, clearinghouse and billing logins, VPN, and admin portals—password-only access remains the cheapest way into a small practice.
- Verify immutable backups of EHR exports or vendor-held data, scanned documents, shared drives, and practice-management data—and run a restore test this month.
- Inventory vendor remote access (managed IT, EHR vendor, billing service, lab interfaces): unique named accounts, MFA, time-bounded sessions, and a documented revoke path.
- Retire shared front-desk and provider logins and keep an up-to-date user list
- Rehearse paper downtime and brief staff on post-headline phishing: printed schedules, a refill workflow, and a rule that unexpected links, portal resets, or payment requests are verified by a known phone number, not the email thread.
Brotherly Technology helps medical, dental, and specialty practices across Rome, Northwest Georgia, metro Atlanta, and our TN/AL/NY (Wallkill) footprint turn healthcare cyber headlines into a short HIPAA-minded continuity review—without inventing details a named practice has not confirmed. The Booba Project claim against Raleigh Family Medicine is a timely reminder to run that drill now.
Sources:
- Ransomware.live — Raleigh Family Medicine / Booba Project — Discovery ~2026-10-02 12:51 UTC; attackdate ~2026-10-02 12:30 UTC; U.S. healthcare listing; claim-level only.
- Raleigh Family Practice (rfppa.com) — Practice context: independent, provider-owned family practice in Raleigh, NC; no incident acknowledgment cited here.