On 31 August, Policlinico Triestino S.p.A., which comprises several healthcare facilities, suffered a data breach perpetrated by the INCRansom group. Given the seriousness of the incident, the type of organisation affected and the nature of the data processed, the case has been referred to Deputy Public Prosecutor Cristina Bacer; so far, this is nothing new compared with the many other data breaches we have come to expect.
What was exfiltrated?

Apparently, the cyber attack should not have compromised patient data; indeed, the company issued a statement saying that“patient data is secure and has not been compromised” (Source: Il Nuovo Terraglio), but the truth may be slightly different – and worse.
The risk of healthcare data being exposed
At the time the stolen data was released, the hackers may have published patients’ health information from facilities such as Pineta City; if this were the case, there would also have been a leak of highly sensitive diagnostic information, often linked to diagnostic tools and not merely to referral activities. Indeed, the hackers appear to have also gained access to a folder named “DicomData”, which may well contain precisely this kind of health information.

DICOM is, in fact, the universal standard for medical imaging that enables biomedical data to be viewed, stored, printed and exchanged between different medical devices and software. In fact, the publication of data in that folder could affect over 1,120 patients involved in the data breach; it is worth remembering that healthcare data is a special category of personal data precisely because of its importance. INCRansom demanded a ransom of 81.7 million dollars to prevent the publication of the data, which the company obviously did not pay. On 10 September 2026, Policlinico Triestino S.p.A. issued an official statement on its institutional website, which reads:
Investigations and analyses into the cyber-attack are still ongoing, with the support of the relevant authorities. The incident is linked to the INC Ransom ransomware group, and Policlinico Triestino S.p.A. has, from the outset, ruled out any possibility of paying the ransom and, consequently, has not entered into any negotiations with the criminal organisation.
It should also be noted that the Group’s subsidiaries were not affected by the incident and that there are no links between their respective IT infrastructures.
We will continue to provide updates on how the situation develops, and we would like to thank our patients, our IT partners and all our staff for their cooperation over the past few days.
The clarification in bold highlights a crucial aspect of the matter. It will therefore be necessary to ascertain whether the statements the company made to the press and included in the press release are in fact correct – and whether, consequently, patients’ data‘are secure and have not been compromised’ – or whether INCRansom has in fact also stolen and published the diagnostic images of the healthcare facility’s patients. The relevant authorities will have no choice but to establish the facts and determine who is responsible for the incident, as well as whether healthcare data has been properly safeguarded.