The ransomware claim alleges that the threat actor safepay targeted drcloudemr.com, a provider of cloud-hosted EHR and practice management software for ambulatory clinics. The attack occurred in the United States, impacting healthcare facilities reliant on DrCloudEHR. #UnitedStates
Incident Details
- Victim: drcloudemr.com
- Country: US
- Actor: safepay
- Source: http://safepaypfxntwixwjrlcscft433ggemlhgkkdupi2ynhtcmvdgubmoyd.onion/blog/post/drcloudemrcom/
- Discovered: 2025-09-17 20:12:15.237508
- Published: 2025-09-17 20:12:02.400583
Information
- Ransomware attack targeted drcloudemr.com in the US.
- Perpetrated by the actor safepay.
- DrCloudEHR offers cloud-hosted electronic health record (EHR) and practice management software.
- The software is primarily aimed at ambulatory clinics.

Disclaimer: This post is based on public claims made by the ransomware group "safepay". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.