Kettering Health is the second-largest employer in the Dayton region: fourteen or fifteen medical centers depending on the year, more than a hundred and twenty outpatient sites, Kettering College, and annual revenue around $2.5 billion. It exists because the Kettering family invited the Seventh-day Adventist Church to run a hospital named after Charles F. Kettering, the Delco co-founder and General Motors engineer. It is a charity. The money it holds is charitable money, and Ohio law puts the attorney general in charge of protecting it.
In 2021, employees and church members started telling the state that money was leaving the building for reasons that had nothing to do with patients. What followed has been slow, partial, and — five years on — legally unresolved. This page sets out what has been established, what remains an allegation, and what has not happened.
What the hospital found
The network's board opened an internal investigation in the autumn of 2021 and brought in an outside firm. A forensic audit was completed in 2023. On 7 November 2023, the new chief executive, Michael Gentry, told staff by email that the review had finished and that organizational funds had been used for purposes that were not business purposes. Kettering Health said it would seek repayment from multiple individuals and pass information to the appropriate authorities, and that everyone implicated had left the organization.
At the time it named no one and disclosed no amount. An initial version of its public statement referred to senior executives and board members; that wording was later softened to individuals.
The numbers only became public more than two years later. Kettering Health had filed amended tax returns in 2024 disclosing the audit's findings, and in January 2026 the Dayton Daily News obtained them. The filings identify 46 people who received excess benefits totalling more than $3.2 million between 2016 and 2022: former hospital executives, current and former senior Adventist church officials, local business figures, and family members of all three groups.
| Recipient | Benefits |
|---|---|
| Fred Manchur, chief executive 2010–2022, and Mary Kaye Manchur Recorded as having repaid nothing |
~$1,500,000 |
| Dave Weigley, board chair and Columbia Union president, and his wife | ~$293,000 |
| 44 further individuals, including hospital executives, Ohio Conference and Columbia Union officers, one North American Division officer, and family members | balance of $3.2M+ |
The itemised expenditures are what gave the story its shape in the local press: a whale-watching trip in Maui billed at $12,124, a spa retreat at $21,250, travel and lodging in Rome and Paris and Hawaii, decorations for the Manchurs' private home, and a long tail of gifts and floral orders from two Dayton-area vendors, many over $100 and one as high as $1,412. Transactions involving one family included European travel logged as a growth retreat and Hawaii travel logged as a spiritual retreat.
What "excess benefit" means, and why the phrase matters
It is not a euphemism a press officer invented. It is a term of art from section 4958 of the Internal Revenue Code. An excess benefit transaction is one in which a tax-exempt organization gives an insider — an executive, a board member, a family member — something worth more than what the organization gets back.
The consequences fall on the recipient, not the charity. The person owes an excise tax of 25 per cent of the excess, rising to 200 per cent if it is not corrected within the statutory period. Organization managers who knowingly approved the transaction can owe 10 per cent. Correcting it means paying the money back with interest. This is why the repayment column is the one that matters in the filings: an uncorrected excess benefit is an open tax liability, not a closed matter.
None of this is a criminal finding. Section 4958 is a civil tax mechanism. Whether anything here amounted to a crime is the separate question the Ohio attorney general has been sitting on since 2021.
The complaint trail
It is commonly described as though one whistleblower came forward. The public record shows at least four separate channels, running over about eighteen months.
- 2021 — an open letter. An anonymous letter signed by people identifying themselves as concerned Adventist church members and friends of Kettering Health was circulated to network staff, church officials and government officials, listing concerns about spending.
- August 2021 — a named complaint. Lori Van Nostrand, then an executive secretary at Soin Medical Center, filed with the attorney general over Manchur's expense reports, entertainment costs and property decisions.
- An employee complaint. A complainant identifying as an employee alleged Manchur had the chief financial officer withhold true financials from board meetings and that minutes were altered to suggest votes had occurred.
- February 2023 — a further anonymous complaint sent to Attorney General Yost, covering network spending on travel and other costs, including the allegation about the Manchur house.
Separately, a letter criticising Manchur circulated among hospital staff before his departure. Van Nostrand says she was retaliated against for supporting it, resigned in February 2022, and filed with the Ohio Civil Rights Commission.
The other complainants have stayed anonymous, and there is a reason for that. The one person who put her name to a complaint says it cost her her job. Nobody outside the attorney general's office knows who the others are, and identifying them is not a public service.
What people have said on the record
Most of the pointed commentary in this story has come from people who agreed to be named. That matters, because it is checkable.
Jim Londis — corporate integrity officer, Kettering Health Network, 1998–2008
Londis, a longtime Adventist pastor, ethics scholar and administrator, told Spectrum that across his decade in the role, "no one ever filed any complaint analogous to the ones alleged." He added that it saddened him to think it might be happening now. He is describing the period immediately before Manchur became chief executive, which makes his statement a marker for when the pattern is alleged to have started.
Ted L. Ramirez — Ohio attorney
Ramirez spent forty years as legal counsel to Adventist health institutions, including Loma Linda University Medical Center, Kettering Health on mergers and governance, and the General Conference. Speaking in December 2022, he said past and current Kettering employees had been calling his office reporting that investigators and lawyers were contacting them. He said few people in Ohio's legal, business and health care communities regarded the retirement account as the whole story, and described callers as variously puzzled, hurt and frightened, hoping those who remained could change the institution's direction.
A dozen health care executives — anonymous, to Spectrum
Speaking on condition of anonymity over fear of reprisal, they described a reputation that had followed Manchur across a career beginning with twenty years at Adventist Health in California. The recurring theme was an absence of separation between personal and institutional interest, and a culture in which accepting the perks was the price of staying in favour. These are anonymous characterisations, not findings.
Wally Sackett — former Kettering Health president
Covered in the pushback section below.
Robert Gresham and Richard Schulte — Wright & Schulte LLC
The Vandalia law firm representing patients in the cyberattack litigation. Gresham has said the case is about care that was cancelled, delayed or never rescheduled after the 2025 system failure. Schulte has argued the network had a duty to communicate the nature of the breach and did not meet it.
Josh Sweigart — Dayton Daily News
The investigations editor who broke the tax-filing story has been explicit that the 2023 audit's existence was announced without scope, headcount or dollar figure, and that the numbers surfaced only when his newsroom went after the filings.
The family payroll
Running underneath the expenses story is a longer-standing pattern the local paper had already flagged. In 2011, the Dayton Daily News reported that Kettering Health Network employed executives' relatives more often than other health systems in the region. That was eleven years before Manchur's departure.
By 2021, the network's IRS disclosures showed the following.
| Person | Reported |
|---|---|
| Fred Manchur, chief executive Base pay, plus a $407,160 bonus and $82,317 other reportable compensation |
$1.6M+ base |
| Richard Manchur, his son, president of Kettering Health Dayton from 2019 | $830,952 |
| Jared Keresoma, his son-in-law, vice president of operations, Greene Memorial Hospital | $419,435 |
Manchur's base pay ran between $1.2 million and $1.5 million from 2015 to 2020, with bonuses typically between $390,000 and $465,000. His largest reported year was 2017, when total compensation exceeded $5 million, including more than $3.4 million in other reportable compensation.
Both whistleblower complaints raise the appointment of Richard Manchur as president of Kettering Health Dayton, alleging it did not go through board approval. He was replaced in August 2023, eight months after his father retired; the network said he left to pursue other opportunities.
The house on Stonebridge Road
This is the single most concrete document trail in the story, and it predates everything else by more than a decade.
On 1 April 2008, Kettering Medical Center signed a purchase agreement to buy a historic house on Stonebridge Road, directly behind the hospital campus, for $1 million, subject to board approval. The agreement was signed by the hospital's then chief financial officer, Russ Wetherell. The seller did not sign it.
Six weeks later, on 16 May 2008, Fred Manchur — then president of Kettering Medical Center — and his wife bought the same house themselves for $1 million. The seller also gave them $43,361 for repairs. Whether the board ever discussed or voted on the hospital's own proposed purchase is not known; when the Dayton Daily News asked in 2023, a network spokeswoman said she could provide no information.
The Manchurs still own the property. It runs to more than 15,000 square feet and the county auditor now values it at roughly $2.5 million. Decorations for the house appear among the expenditures the 2023 audit flagged as improper.
The pushback
Kettering Health's own framing has been notably protective of most of the 46. The network says several people were led to believe the trips, meals and gifts were legitimate business activity or acceptable presents, and had no reason to think otherwise until the investigation concluded and they were notified. It says the large majority chose to repay.
Wally Sackett, a former Kettering Health president who left the organization in October 2022, went further in public. He argued that reading the tax filings as a record of misuse of funds should be applied narrowly, and said most people on the list, himself included, did what they could to correct the discrepancies once identified. He also made a structural point worth taking seriously: an outside firm brought in to conduct a forensic audit may scrutinise costs in ways the network's own compliance and audit committees never had, and executives would not have known those concerns existed until they were raised.
That distinction is real. A list of 46 names is not a list of 46 wrongdoers. The filings themselves separate those who corrected from those who did not, and the Manchurs sit at the top of the second group. Andrea Jakobsons, whose family's travel appears among the flagged transactions, declined to comment.
The church dimension
What makes this more than a regional hospital story is the governance structure behind it. Adventist health systems in the United States seat denominational officers on their boards, and Kettering Health is no exception. Dave Weigley chaired the Kettering Health board while serving as president of the Columbia Union Conference — the same church body whose leaders appear on the recipient list alongside Ohio Conference officers and a North American Division officer.
The chair of a charity's board is the person whose job is to catch exactly this.
The internal accountability was thin. Weigley announced Manchur's interim replacement, then left the board in January 2023, saying at the time that he was stepping down because of his wife's illness. Roy Chew, a board member who had written a warm public tribute to Manchur on his retirement, was appointed to lead the search for his successor. More than a hundred current and former employees signed that same tribute board.
The Columbia Union issued a statement in March 2023 saying Kettering Health had made clear that issues identified through the investigation were being addressed immediately, and affirming its own commitment to accountable leadership and good stewardship. That was its last substantive public comment.
Weigley retired abruptly from the Columbia Union presidency on 1 March 2024. Marcellus T. Robinson, previously president of the Allegheny East Conference, was voted in by a special executive committee session that month and re-elected at the union's constituency meeting on 16 May 2026.
The second story: the 2025 ransomware attack
This is a separate matter from the money, and it was not concealed — it was impossible to conceal, because the hospitals stopped working. But it is the larger event by any measure of harm, and it is where Kettering Health currently faces the most legal exposure.
- Patients whose data was compromised
- 1,695,382
- Days attackers were inside the network before detection
- 41
- Data exfiltrated, as claimed by the attackers
- 941 GB
- Months the official victim count sat at a placeholder of 501
- ~9
What happened
The Interlock ransomware group entered Kettering Health's network on 9 April 2025 and was not detected until 20 May, when the system went down. Roughly 600 digital applications were shut off. Staff reverted to paper. Emergency departments diverted ambulances until 28 May. The Epic electronic health record came back on 2 June; the network declared normal operations restored on 10 June.
Kettering Health declined to pay, and Interlock published the stolen files. Beyond patient records, the trove by folder name appeared to include payroll records, employee files, scans of identity documents, security personnel files, Medicaid applications, pharmacy and blood bank records, corporate insurance and tax material and budget reports. This was not only a patient breach; the network's own staff were in it.
The compromised data includes names, addresses, dates of birth, Social Security numbers, taxpayer identification numbers, driver's licence and state ID numbers, passport numbers, medical record numbers, diagnosis and treatment information, insurance and billing information, financial account and card information, education records, and in some cases usernames with their associated passwords.
Who Interlock are
Interlock surfaced in September 2024 and has concentrated on healthcare, with DaVita, Texas Tech University Health Sciences Center and a US military supplier among its claimed victims. Researchers have noted similarities to the Rhysida ransomware family.
Its method matters for assessing fault. Interlock does not generally rely on phishing or exposed remote desktop. The FBI has documented drive-by downloads from compromised legitimate websites — unusual among ransomware crews — and ClickFix, in which a user is shown a fake CAPTCHA or error message and told to paste a command into the Windows Run box, making the victim the delivery mechanism. The group then deploys remote access trojans and tooling such as Cobalt Strike, and encrypts virtual machines across Windows and Linux, which is how a single well-placed action can take down an entire estate at once. Its ransom notes carry no initial demand or payment instructions.
One point of fairness: the joint FBI, CISA, HHS and MS-ISAC advisory on Interlock (AA25-203A) was published on 22 July 2025, two months after the Kettering attack. The network was not ignoring a specific federal warning about this group. It was, however, a healthcare organization in a year when healthcare was the sector Interlock was known to be working through.
The people it happened to
Local television followed individual patients from the first week, which is why this part of the record is unusually well documented.
Doris Roberts of Clayton had been diagnosed with stage 4 pancreatic cancer in April 2025. She had received one chemotherapy treatment. The second was cancelled by phone the day before the attack became public, and she spent the following weeks waiting for a call, saying her fear was that the cells were spreading while she waited. Her treatment resumed after about two weeks. She later joined the litigation, saying her main concern by then was that nobody file insurance claims in her name.
Lealon Mitchell told reporters in the first days that his wife's heart was barely functioning and her scheduled surgery had been delayed, with no clarity on when it would happen.
Mishelle Holder of Dayton is the lead plaintiff in the mass tort series. Her claim concerns a surgery on a blocked artery in her left leg and the pain she says followed.
The notification gap
This is the sharpest criticism available, and it holds up.
The breach was reported to the federal Office for Civil Rights on 21 July 2025 with a placeholder figure of at least 501 affected individuals. Kettering Health did not confirm the categories of compromised data until October 2025. Individual notification letters did not reach patients until around February 2026. The real figure of 1,695,382 did not appear on the federal portal until roughly April 2026.
That is about nine months before people were told their Social Security and passport numbers were exposed, and eleven months before the scale was public — all of it running after the attackers had already published the files in June 2025. The exposure was live the entire time the number sat at 501.
Kettering Health's own account is that the file review genuinely took that long, which is a common and not unreasonable explanation in breaches of this size. The counter-argument, which the plaintiffs are making, is that the data was already published and the delay ran entirely against the people whose information was in it.
The litigation
Two tracks, with different mechanics.
The first is a conventional data-breach class action in Montgomery County Common Pleas Court, alleging the network understood the risk of a breach, failed to protect patient data, and did not meet regulatory guidance or industry-standard practice.
The second is unusual and is the one to watch: mass tort personal injury claims over care that did not happen. These are individual claims rather than a class, which means individualised damages and the possibility of different outcomes case by case. Attorneys Michael Wright and Richard Schulte of Wright & Schulte say they have filed more than 200 care-related suits and represent more than 500 further people over stolen data. Forty-four were consolidated under a master complaint before Judge Angelina Jackson, originating from a personal injury filing in October 2025. Of those 44, 37 allege delayed treatment, 8 allege outright denial of care, and one alleges both, across more than fifteen Kettering Health locations. The master complaint pleads negligence, gross negligence, emotional distress, breach of contract and claims against unidentified parties. Plaintiffs seek compensatory damages over $25,000, punitive damages and fees, and a jury trial.
The plaintiffs' central allegation is not that Kettering Health was breached. It is that it had no adequate plan for a foreseeable cyberattack, and that when the systems went down it stopped seeing patients rather than falling back on a functioning manual process.
Kettering Health does not comment on pending litigation. Its public position, stated in its own incident FAQ, is that external partners and internal teams removed all threats, that network segmentation, enhanced monitoring and updated access controls are in place, and that it is confident its cybersecurity framework and employee security training are sufficient to mitigate future risks. That last sentence is the kind of statement plaintiffs' counsel tends to read back to a jury.
As of the end of August 2026 there is no reported settlement in either track, and no announced enforcement action by the HHS Office for Civil Rights. An OCR breach report is not an OCR investigation finding, and the portal entry does not by itself indicate any determination of fault.
What has been withheld
Kettering Health has not been silent, but it has been consistently selective. The following are matters on which it has declined to answer, all documented in contemporaneous reporting.
- The name of the outside firm that conducted the 2023 forensic audit, and whether any report would be made public. Both questions were put by Spectrum in 2023 and declined.
- The number of people involved and the amount of money, in the November 2023 announcement. Both became public knowledge only because a newspaper obtained the tax filings two years later.
- Whether the board discussed or voted on the 2008 proposal for the hospital to buy the Stonebridge Road house.
- Whether any further money was repaid after the excess benefits were reported to the IRS in 2024.
- The financial terms of its 2022 sponsorship agreement making it the official health care provider of the Cincinnati Bengals, on the grounds that it does not disclose agreements with community partners.
Add to that the amendment of its own statement from "senior executives and board members" to "individuals," and the eleven-month gap before the real breach figure was filed, and there is a discernible pattern: disclosure that is accurate as far as it goes, and goes no further than it has to.
What doesn't hold up
Some things that circulate about Kettering Health do not survive checking, and a page like this is worth less if it does not say so.
- Donor funds. Kettering Health stated in March 2023 that the allegations did not involve the Kettering Health Foundation and that its investigation confirmed as much. No published reporting has contradicted this. The money at issue is operating money, not gifts from donors.
- The 2022 losses. Financial statements to 30 September 2022 show a $280 million loss and a swing of more than $400 million in under a year. Coverage at the time attributed this mainly to investment income tracking the stock market, alongside wage inflation affecting the whole sector. It is not evidence of theft.
- Layoffs. The most-cited example is the August 2025 restructuring of the accounts payable department, affecting no more than 11 full-time positions. That is ordinary. Larger "Kettering layoffs" stories in circulation generally concern Memorial Sloan Kettering in New York, a completely unrelated institution.
- The ransomware attack as a cover-up. It was disclosed within hours and reported continuously. The fair criticism concerns the pace of breach notification and the adequacy of contingency planning, not concealment of the incident.
- Nicknames and anecdotes. Colourful characterisations of Manchur circulating in Adventist administrative circles come from executives speaking anonymously. They are published, but they are impressions, not evidence, and nothing on this page rests on them.
Where it stands
The Ohio attorney general's office opened its investigation into alleged inappropriate expenditure of charitable funds by Kettering Health executives and board members in 2021. It is still open.
Ohio's charitable law requires that such investigations stay confidential until charges are filed, which is why successive attorneys general have said almost nothing. Dave Yost said in March 2026 that he could neither confirm nor deny an investigation but expected to be able to say more later in the year; he left office in June. His successor, Andy Wilson, sworn in on 5 June 2026, was asked for an update in August and said they were "not there yet," adding that the office would put the information out when the time came.
Most recent public statement from the Ohio attorney general's office. No charges filed. Investigation confirmed ongoing.
The clock is the live problem. Misuse of nonprofit funds in Ohio is generally prosecuted under misappropriation or fraud statutes, which commonly run four years from discovery, though various circumstances can extend that. The complaints were filed in 2021. The forensic audit finished in 2023. Van Nostrand has said publicly that the reporting has barely scratched the surface, that it is frustrating to watch the limitation period likely run out, and has asked the attorney general, in as many words, to do something.
Timeline
Fred Manchur becomes president of Kettering Medical Center after twenty years with Adventist Health in California.
Kettering Medical Center signs an agreement to buy a house on Stonebridge Road for $1 million, pending board approval. Six weeks later the Manchurs buy it themselves.
Manchur is named chief executive.
The Dayton Daily News reports the network employs executives' relatives more often than other local health systems.
An anonymous letter from self-identified concerned Adventist church members circulates to staff, church officials and government officials.
Lori Van Nostrand files a complaint with the Ohio attorney general's office.
Kettering Health's board opens an internal investigation. The attorney general's office opens its own.
Van Nostrand resigns from Soin Medical Center, alleging retaliation. She later files with the Ohio Civil Rights Commission.
Manchur's retirement is announced, effective 21 December, with a leave of absence beforehand. No successor is named for six days.
Manchur retires. Chief financial officer Michael Mewhirter becomes interim chief executive. Spectrum publishes the first reporting on governance questions.
Dave Weigley leaves the Kettering Health board, citing his wife's illness. Celeste Ryan Blyden becomes chair.
A further anonymous complaint is sent to Attorney General Yost.
WHIO-TV obtains the complaints through a public records request. Kettering Health confirms it has hired outside firms, and says the allegations do not involve its Foundation.
The Dayton Daily News publishes the Stonebridge Road purchase documents.
Michael Gentry, formerly of Sentara Healthcare and AdventHealth, takes over as chief executive.
Richard Manchur is replaced as president of Kettering Health Dayton. Several other senior figures depart.
Gentry tells staff the investigation found organizational funds used for non-business purposes. No names, no figures.
Kettering Health reports the excess benefits to the IRS in amended tax filings.
Weigley retires abruptly as Columbia Union president. Marcellus T. Robinson is voted in.
The Interlock ransomware group enters Kettering Health's network. It goes undetected for 41 days.
Systems collapse. Around 600 applications go offline, staff revert to paper, emergency departments divert ambulances.
The breach is reported to federal regulators using a placeholder estimate of 501 people.
Kettering Health confirms what categories of patient data were taken. The count is still unresolved.
The Dayton Daily News publishes the amended filings: 46 people, more than $3.2 million, the Manchurs at the top and recorded as having repaid nothing.
Forty-four cyberattack suits are consolidated before Judge Angelina Jackson. The firm says more than 200 have been filed for roughly 700 people.
The federal breach portal is finally updated: 1,695,382 individuals affected.
Attorney General Dave Yost leaves office. Andy Wilson is sworn in and inherits the case.
Wilson declines to give details. Still no charges, five years after the first complaint.
Who's who
Fred Manchur
Chief executive, Kettering Health, 2010–2022; president of Kettering Medical Center from 2001
Named in whistleblower complaints as a central figure. He and his wife top the excess-benefits list at roughly $1.5 million and are recorded as having repaid nothing. He has not responded to press requests for comment. He has not been charged.
Dave Weigley
Kettering Health board chair; president, Columbia Union Conference, 2006–2024
Named alongside Manchur in the complaints. He and his wife appear on the list at roughly $293,000. Left the board in January 2023 citing his wife's illness, and retired from the union presidency in March 2024. He has not been charged.
Richard Manchur
President, Kettering Health Dayton, 2019–2023
Fred Manchur's son. Reported at $830,952 in 2021 compensation. Complaints allege his appointment bypassed the board. Left in August 2023; the network said he departed to pursue other opportunities. He has not been accused of receiving improper benefits.
Michael Gentry
Chief executive, Kettering Health, from July 2023
Arrived after the events under investigation. Announced the internal findings to staff, the decision to pursue repayment and refer information to authorities, and led the response to the 2025 cyberattack.
Lori Van Nostrand
Former executive secretary, Soin Medical Center; whistleblower
The only complainant to have put her name to a filing publicly. Says she was retaliated against and resigned in 2022. Has criticised the pace of the state investigation and says more remains uncovered.
Jim Londis
Corporate integrity officer, Kettering Health Network, 1998–2008
States that no comparable complaint was filed during his decade in the role.
Andy Wilson
Ohio attorney general, from June 2026
Inherited the investigation from Dave Yost. Bound by state confidentiality law and has declined to characterise its status beyond saying it is not yet at a point he can discuss.
The open questions
- Whether the attorney general will bring charges, or has already concluded he cannot, and whether the four-year window has closed on the earliest conduct.
- Whether Kettering Health recovered anything from those recorded as having repaid nothing, and what it did when they refused.
- Whether the IRS pursued the excise tax liabilities that uncorrected excess benefits create.
- Whether the board ever voted on the 2008 hospital purchase of the Stonebridge Road house, and what became of that proposal.
- What the Adventist church structures did internally about officers who appear on the list and remain in denominational employment.
- Why the federal breach count took eleven months to move off a placeholder of 501 when the attackers had published the files in June 2025.
- Whether the two stories are connected in any way beyond timing. There is no published evidence that they are.