A collection agency is facing lawsuits, lost contracts, and more after being the victim of a data breach last year that is now being disclosed. Nationwide Recovery Services, a Tennessee-based debt collection agency, suffered a cybersecurity breach in July 2024 that has since triggered lawsuits, government contract cancellations, and breach notifications affecting more than 300,000 individuals tied to multiple healthcare providers.
NRS was targeted by a cyberattack between July 5 and July 11, 2024. Threat actors accessed and exfiltrated files from NRS systems during that time, leading to the exposure of sensitive data including Social Security numbers, birth dates, financial account details, and medical information. It wasn’t until this past February that NRS notified one of its major clients, Harbin Clinic, that its patients’ data may have been impacted. A full list of 210,140 affected individuals was not shared until March. The delayed disclosure has become a focal point of criticism from data security experts and a point of contention in legal filings.
NRS is licensed in all 50 states and manages collections for delinquent medical accounts, legal matters, bankruptcies, and estates. Its client list spans large regional healthcare systems, including Harbin Clinic, Vitruvian Health, Elbert Memorial Hospital, and the City of Chattanooga, according to published reports.
These clients are now dealing with the reputational and legal fallout. The city of Chattanooga rescinded its $220,000 annual contract with NRS, and lawsuits have been filed in federal court by individuals in Georgia, New York, and North Carolina.
One suit alleges that “the defendants were negligent, broke implied contracts, and used profits from patients without improving security.” Another accuses NRS and its clients of violating federal privacy laws and delaying breach notifications, compounding the harm.
Experts say breaches like this are a wake-up call for healthcare providers and financial services firms that outsource sensitive functions to third-party vendors.
“Debt collection firms like NRS are part of the back-end administrative chain that often gets overlooked in cybersecurity investments,” said Ensar Seker, CISO at SOCRadar, in a published report. “They handle high-value datasets but often don’t match the security maturity of their clients.”




