A ransomware group calling itself Direwolf claims it stole internal data from Hazel Health, a telehealth provider used by more than 180 school districts nationwide. Hazel Health has not confirmed the claim, and no notice has gone out to families yet — but Emery | Reddy is opening an investigation now, before any formal notice arrives.
Hazel Health, Inc. is a San Francisco-based telehealth company that provides physical and mental health services to public school students at no cost to families, under contract with more than 180 school districts across 19 states — including some of the largest districts in the country, such as Los Angeles, Philadelphia, Houston, Miami, and Clark County, Nevada. Hazel Health delivers care through affiliated professional corporations, including Telehealth Services USA PC, and operates as an organized health care arrangement for HIPAA purposes. On September 14, 2026, the ransomware group Direwolf listed Hazel Health on its dark web leak site, claiming to have stolen internal data from the company. As of this writing, Hazel Health has not publicly confirmed the claim, and no notice has been sent to affected families.
Source: Direwolf ransomware group leak-site posting, dated 09/14/2026, tracked via GalaxyWarden and independently corroborated on RansomLook (posting dated 09/14/2026). This is the attacker’s own claim, not an admission by Hazel Health, and has not been independently verified.
Who Is Direwolf?
Direwolf is a double-extortion ransomware-as-a-service operation that has been active since approximately May 2025. Like other double-extortion groups, Direwolf typically steals data before encrypting a victim’s systems, then threatens to publish the stolen files unless a ransom is paid — using the threat of a public leak as additional leverage beyond the encryption itself.
What We Know — and What We Don’t
This is important to say plainly: a listing on a ransomware group’s leak site is an extortion tactic, not proof that a breach occurred. Groups like Direwolf post claims to pressure a company into paying, and some listings turn out to be exaggerated, recycled from old incidents, or false altogether. The public record right now doesn’t include a count of how many people may be affected or a list of what specific information the group claims to have taken. As of September 21, 2026, Hazel Health has no breach notice on file with the California Attorney General, and no posting has been located on the U.S. Department of Health and Human Services’ HIPAA breach portal. No lawsuit has been filed yet, which isn’t unusual — the claim is barely a week old. We’re treating this as an unconfirmed claim and will update this post if and when Hazel Health, a regulator, or independent forensic evidence confirms more.
A Separate, Earlier Incident — Not the Same Thing
Families researching Hazel Health online may also come across reporting from December 2025 about Prince William County Schools in Virginia accidentally sharing student and parent data with Hazel Health for families who hadn’t opted into its services. That earlier incident was a school district’s own disclosure mistake, not a hack of Hazel Health’s systems, and the district said the data was destroyed once the error was found. It is a separate matter from the new ransomware claim described in this post, and the two should not be confused.
Source: WTOP and InsideNoVa reporting on the December 2025 Prince William County Schools data-sharing incident, cited here only to distinguish it from the new September 2026 ransomware claim.
Why We’re Investigating Now, Before Any Notice Goes Out
If Direwolf’s claim is accurate, Hazel Health will eventually be required to notify affected families directly, typically by mail. That notice could still be weeks or months away — breach investigations at healthcare and telehealth companies often take significant time to complete. Emery | Reddy is opening an investigation now so that families who use Hazel Health’s services are ready to act as soon as more information becomes available, rather than starting from scratch once a notice letter finally arrives.
What Families Can Do Now
- If your child receives services through Hazel Health at their school, keep an eye on your mail and email for a notice letter
- Watch for phishing attempts referencing your child’s school or Hazel Health, especially if the claim is later confirmed
- Contact us to be included in our investigation, so we can reach you directly if and when this claim is confirmed
Do You Have Legal Options?
Companies that provide healthcare services to children through school partnerships have a legal duty to secure the personal and health information they collect. If this claim is confirmed, families may have legal options.
If your child uses Hazel Health’s telehealth services, contact Emery | Reddy today to be included in our investigation.
FAQ
Has Hazel Health confirmed a data breach?
No. As of this writing, Hazel Health has not publicly confirmed the Direwolf ransomware group’s claim, and no filing has been made with the California Attorney General or HHS. This is currently an unverified accusation from a criminal extortion group.
How many people are affected?
The leak-site listing does not include a count of affected individuals or a list of specific data categories. No population figure is currently available from any source.
Is this related to the Prince William County Schools incident from December 2025?
No. That was a separate incident involving a school district accidentally sharing data with Hazel Health, which the district said was destroyed once discovered. This post concerns a new, unrelated ransomware group’s claim from September 2026 involving Hazel Health’s own systems.
Has anyone filed a lawsuit yet?
No. As of September 21, 2026, no lawsuit has been identified related to this claim. That’s typical for a claim this recent — the leak-site posting is only about a week old.
Why are you writing about this before Hazel Health has sent any notice?
Breach investigations and formal notice can take months. We’re opening our own investigation now so that families are prepared to act quickly once more information is confirmed, rather than waiting until a notice letter arrives.
Do I have a legal claim?
Companies that provide healthcare services to children through school partnerships have a legal duty to secure the personal and health information they collect. If you or your child use Hazel Health’s telehealth services, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.