Yes — Resource Corporation of America (“RCA”) confirmed unauthorized access to certain systems. The Houston-area medical billing business associate posted a preliminary notice stating it learned of suspicious activity on December 17, 2025, and that unauthorized actors accessed systems and copied files between December 9–17, 2025. Potentially involved data may include names, addresses, DOB, SSNs, health insurance, and medical diagnosis / treatment information.
HHS OCR lists the entity (TX, Business Associate) with a February 13, 2026 submission: Hacking/IT Incident, Network Server, 501 individuals, under investigation. Treat 501 cautiously — HIPAA Journal notes many February 2026 rows use 500/501 as placeholders until reviews finish.
Ransomware groups Medusa and Qilin publicly claimed RCA; RCA’s notice does not name those actors. No Texas federal “Data Breach” consolidation appeared in our CourtListener pass for this entity — coverage here is OCR + org notice driven.

What Happened
| Field | Detail |
|---|---|
| Entity | Resource Corporation of America (resource-corp.com) — Clear Lake Shores / Houston, TX |
| Role | HIPAA business associate (medical billing) |
| Access window | Dec 9–17, 2025 (per RCA notice) |
| OCR | Filed 2026-02-13; 501 individuals (may be placeholder); under investigation |
| Actor claims | Medusa / Qilin (unverified by RCA) |
| Org notice | RCA preliminary notice · phone 844-726-0950 |

Independent Cybersecurity Audit
EmailMeNow audit of resource-corp.com on August 5, 2026. 100% is the ideal.
| Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|
| resource-corp.com | 47% | 35% | 15% | 40% | Below Average |

Key findings: 47% overall — well below 100% for a BA holding PHI; 15% transport and 35% identity raise spoofed “RCA billing / benefits” phishing risk while the file review continues.
Audit link: resource-corp.com
Website-tech · blacklist · lookalikes · MFA
| Check | Result (Aug 5, 2026) |
|---|---|
| Website-tech | WordPress 7.0.2 (current); Sectigo TLS |
| Blacklist | Clear on checked mail/domain lists |
| Cybersquat | 5 to review (resources-corp.com, resourcecorp.com, TLD swaps) |
| YubiKey / open TOTP | Not documented → Unevaluated |
Priority Actions
If you received care billed through RCA or a provider letter: Call only the number on the official notice; freeze credit if SSN was listed; watch medical-identity theft on EOBs.
For healthcare BAs: Close transport/identity gaps toward 100%; segment billing PHI from public CMS hosts; prepare OCR count updates when reviews finish.
Related Trackers
- Parexel Oracle EBS Texas notice
- PsychPlus Gentlemen litigation (alleged)
- Call-on-Doc alleged breach litigation
- Texas healthcare breaches 2026
- Healthcare AG breach reports 2026
- Texas OAG YTD dashboard
Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting.
Sources: RCA preliminary notice · HHS OCR breach portal · Comparitech — Medusa/Qilin claims · EmailMeNow audit — resource-corp.com