Skip to main content
Jump to a category page

A ransomware group calling itself Pear claims it breached Practi-Cal, Inc., a West Sacramento company whose SpEdCare and Health-e-Kids software handles special education and Medi-Cal billing records for California school districts. Practi-Cal hasn’t confirmed the claim, and no notice has gone out yet — but Emery | Reddy is opening an investigation now.

Practi-Cal, Inc., based in West Sacramento, California, provides school-based Medi-Cal billing, electronic health records, and compliance services — including its SpEdCare and Health-e-Kids platforms and its CRCS/LEA Billing Option Program compliance services — to school districts and county offices of education across California. A ransomware group calling itself Pear claims the breach occurred around August 18, 2026, with the claim publicly surfacing on or about August 20-21, 2026. As of this writing, Practi-Cal has not publicly confirmed the claim, and no notice has been sent to affected families, students, or employees.

Source: Pear ransomware group leak-site posting, tracked and reported by DeXpose (dexpose.io). Incident and disclosure dates as reported by public breach tracking. This is the attacker’s own claim, not an admission by Practi-Cal, and has not been independently verified.

What Kind of Data May Be at Risk

Practi-Cal has not itself confirmed what information, if any, was exposed. A plaintiff law firm that has opened its own intake investigation into this incident has publicly identified the categories of data it believes may be at risk, given the nature of Practi-Cal’s platform: names, addresses, email addresses, and phone numbers, as well as Social Security numbers. Because Practi-Cal’s software processes Medi-Cal eligibility and billing information along with health records tied to special education and school-health services, health information for affected students is also a reasonable concern. None of this has been confirmed by Practi-Cal, a regulator, or independent forensic evidence — it reflects an outside investigator’s assessment of what the platform handles, not a confirmed list of exposed data.

Who Is Affected, If the Claim Is Confirmed

Practi-Cal’s platform is used by school districts and county offices of education throughout California for special education and Medi-Cal billing documentation. If this claim is confirmed, potentially affected individuals would likely include students enrolled in California school districts that use Practi-Cal, SpEdCare, or Health-e-Kids, as well as current and former Practi-Cal employees.

What We Know — and What We Don’t

A ransomware group’s leak-site listing is an extortion tactic, not confirmation that a breach happened. As of September 21, 2026, Practi-Cal has no breach notice on file with the California Attorney General, and no lawsuit has been filed — the only activity so far is a plaintiff law firm’s intake page, which itself states plainly that notices have not yet been sent to affected individuals. We’re treating this as an unconfirmed claim and will update this post if and when Practi-Cal, a regulator, or independent forensic evidence confirms more.

Why This Data Is Especially Sensitive

Practi-Cal’s SpEdCare and Health-e-Kids platforms are built specifically for special education documentation and Medi-Cal billing — meaning the records they hold can include information about a student’s individualized education plan (IEP), health office visits, care plans, prescriptions, and Medi-Cal or other health coverage enrollment. This is a narrower and more sensitive category of information than a typical school records breach: it can reveal a child’s disability status, medical needs, and treatment history, tied directly to their identity as a public school student.

Why We’re Investigating Now, Before Any Notice Goes Out

If Pear’s claim is accurate, Practi-Cal and the school districts that use its software will eventually be required to notify affected families and employees. That notice could still be weeks or months away. Emery | Reddy is opening an investigation now so that families whose children are served through Practi-Cal-using school districts are ready to act as soon as more information becomes available, rather than starting from scratch once a notice letter finally arrives.

What Families and Employees Can Do Now

  • If your child receives special education or Medi-Cal-billed services through a school district that uses Practi-Cal, SpEdCare, or Health-e-Kids, keep an eye on your mail and email for a notice letter
  • Ask your school district directly whether it uses Practi-Cal, SpEdCare, or Health-e-Kids, and whether it has received any communication about this incident
  • Watch for phishing attempts referencing your child’s school, IEP services, or Medi-Cal coverage, especially if the claim is later confirmed
  • Contact us to be included in our investigation, so we can reach you directly if and when this claim is confirmed

Do You Have Legal Options?

Companies that process special education and Medi-Cal billing records on behalf of school districts have a legal duty to secure that information. If this claim is confirmed, affected families and employees may have legal options.

If your child’s school district uses Practi-Cal, SpEdCare, or Health-e-Kids, contact Emery | Reddy today to be included in our investigation.

FAQ

Has Practi-Cal confirmed a data breach?

No. As of this writing, Practi-Cal has not publicly confirmed the Pear ransomware group’s claim, and no filing has been made with the California Attorney General. This is currently an unverified accusation from a criminal extortion group.

How many people are affected?

No official population figure has been released by Practi-Cal or any regulator. A plaintiff law firm’s intake page describes the categories of data it believes may be at risk but does not provide a confirmed number of affected individuals.

What information could be at risk?

An outside investigator’s public assessment identifies names, addresses, emails, phone numbers, and Social Security numbers as categories believed to be at risk, along with possible health information given the platform’s role in Medi-Cal billing and special education records. None of this has been confirmed by Practi-Cal.

How do I know if my child’s school district uses Practi-Cal?

Practi-Cal and its SpEdCare and Health-e-Kids platforms are used by school districts and county offices of education across California for Medi-Cal billing and special education documentation. If you’re unsure whether your child’s district uses this software, you can ask your district directly or contact us for help figuring it out.

Has anyone filed a lawsuit yet?

No. As of September 21, 2026, no lawsuit has been filed. A plaintiff law firm has opened an intake investigation and states on its own page that notices have not yet been sent to affected individuals.

Why are you writing about this before Practi-Cal has sent any notice?

Breach investigations and formal notice can take months. We’re opening our own investigation now so that affected families and employees are prepared to act quickly once more information is confirmed, rather than waiting until a notice letter arrives.

Do I have a legal claim?

Companies that process special education and Medi-Cal billing records on behalf of school districts have a legal duty to secure that information. If your child’s school district uses Practi-Cal, SpEdCare, or Health-e-Kids, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now