An accountability record, compiled from published reporting and public documents. Last updated 31 August 2026.

The Kettering Health ledger

A nonprofit Adventist hospital network in Ohio found that its own executives and church-appointed board members had taken millions in benefits with no business purpose. Five years after the first complaint, no one has been charged.

Excess benefits identified, 2016–2022
$3.2M+
People named in the forensic audit
46
Taken by the former chief executive and his wife
~$1.5M
Criminal charges filed since the 2021 complaint
none

Figures are those the hospital network itself reported to the IRS in amended tax filings, obtained and first reported by the Dayton Daily News in January 2026.

Kettering Health is the second-largest employer in the Dayton region: fourteen or fifteen medical centers depending on the year, more than a hundred and twenty outpatient sites, Kettering College, and annual revenue around $2.5 billion. It exists because the Kettering family invited the Seventh-day Adventist Church to run a hospital named after Charles F. Kettering, the Delco co-founder and General Motors engineer. It is a charity. The money it holds is charitable money, and Ohio law puts the attorney general in charge of protecting it.

In 2021, employees and church members started telling the state that money was leaving the building for reasons that had nothing to do with patients. What followed has been slow, partial, and — five years on — legally unresolved. This page sets out what has been established, what remains an allegation, and what has not happened.

What the hospital found

The network's board opened an internal investigation in the autumn of 2021 and brought in an outside firm. A forensic audit was completed in 2023. On 7 November 2023, the new chief executive, Michael Gentry, told staff by email that the review had finished and that organizational funds had been used for purposes that were not business purposes. Kettering Health said it would seek repayment from multiple individuals and pass information to the appropriate authorities, and that everyone implicated had left the organization.

At the time it named no one and disclosed no amount. An initial version of its public statement referred to senior executives and board members; that wording was later softened to individuals.

The numbers only became public more than two years later. Kettering Health had filed amended tax returns in 2024 disclosing the audit's findings, and in January 2026 the Dayton Daily News obtained them. The filings identify 46 people who received excess benefits totalling more than $3.2 million between 2016 and 2022: former hospital executives, current and former senior Adventist church officials, local business figures, and family members of all three groups.

Reported in Kettering Health's amended IRS filings and related records.
RecipientBenefits
Fred Manchur, chief executive 2010–2022, and Mary Kaye Manchur
Recorded as having repaid nothing
~$1,500,000
Dave Weigley, board chair and Columbia Union president, and his wife ~$293,000
44 further individuals, including hospital executives, Ohio Conference and Columbia Union officers, one North American Division officer, and family members balance of $3.2M+

The itemised expenditures are what gave the story its shape in the local press: a whale-watching trip in Maui billed at $12,124, a spa retreat at $21,250, travel and lodging in Rome and Paris and Hawaii, decorations for the Manchurs' private home, and a long tail of gifts and floral orders from two Dayton-area vendors, many over $100 and one as high as $1,412. Transactions involving one family included European travel logged as a growth retreat and Hawaii travel logged as a spiritual retreat.

What "excess benefit" means, and why the phrase matters

It is not a euphemism a press officer invented. It is a term of art from section 4958 of the Internal Revenue Code. An excess benefit transaction is one in which a tax-exempt organization gives an insider — an executive, a board member, a family member — something worth more than what the organization gets back.

The consequences fall on the recipient, not the charity. The person owes an excise tax of 25 per cent of the excess, rising to 200 per cent if it is not corrected within the statutory period. Organization managers who knowingly approved the transaction can owe 10 per cent. Correcting it means paying the money back with interest. This is why the repayment column is the one that matters in the filings: an uncorrected excess benefit is an open tax liability, not a closed matter.

None of this is a criminal finding. Section 4958 is a civil tax mechanism. Whether anything here amounted to a crime is the separate question the Ohio attorney general has been sitting on since 2021.

The complaint trail

It is commonly described as though one whistleblower came forward. The public record shows at least four separate channels, running over about eighteen months.

Separately, a letter criticising Manchur circulated among hospital staff before his departure. Van Nostrand says she was retaliated against for supporting it, resigned in February 2022, and filed with the Ohio Civil Rights Commission.

The other complainants have stayed anonymous, and there is a reason for that. The one person who put her name to a complaint says it cost her her job. Nobody outside the attorney general's office knows who the others are, and identifying them is not a public service.

What people have said on the record

Most of the pointed commentary in this story has come from people who agreed to be named. That matters, because it is checkable.

Jim Londis — corporate integrity officer, Kettering Health Network, 1998–2008

Londis, a longtime Adventist pastor, ethics scholar and administrator, told Spectrum that across his decade in the role, "no one ever filed any complaint analogous to the ones alleged." He added that it saddened him to think it might be happening now. He is describing the period immediately before Manchur became chief executive, which makes his statement a marker for when the pattern is alleged to have started.

Ted L. Ramirez — Ohio attorney

Ramirez spent forty years as legal counsel to Adventist health institutions, including Loma Linda University Medical Center, Kettering Health on mergers and governance, and the General Conference. Speaking in December 2022, he said past and current Kettering employees had been calling his office reporting that investigators and lawyers were contacting them. He said few people in Ohio's legal, business and health care communities regarded the retirement account as the whole story, and described callers as variously puzzled, hurt and frightened, hoping those who remained could change the institution's direction.

A dozen health care executives — anonymous, to Spectrum

Speaking on condition of anonymity over fear of reprisal, they described a reputation that had followed Manchur across a career beginning with twenty years at Adventist Health in California. The recurring theme was an absence of separation between personal and institutional interest, and a culture in which accepting the perks was the price of staying in favour. These are anonymous characterisations, not findings.

Wally Sackett — former Kettering Health president

Covered in the pushback section below.

Robert Gresham and Richard Schulte — Wright & Schulte LLC

The Vandalia law firm representing patients in the cyberattack litigation. Gresham has said the case is about care that was cancelled, delayed or never rescheduled after the 2025 system failure. Schulte has argued the network had a duty to communicate the nature of the breach and did not meet it.

Josh Sweigart — Dayton Daily News

The investigations editor who broke the tax-filing story has been explicit that the 2023 audit's existence was announced without scope, headcount or dollar figure, and that the numbers surfaced only when his newsroom went after the filings.

The family payroll

Running underneath the expenses story is a longer-standing pattern the local paper had already flagged. In 2011, the Dayton Daily News reported that Kettering Health Network employed executives' relatives more often than other health systems in the region. That was eleven years before Manchur's departure.

By 2021, the network's IRS disclosures showed the following.

Compensation reported on Kettering Health's 2021 Form 990.
PersonReported
Fred Manchur, chief executive
Base pay, plus a $407,160 bonus and $82,317 other reportable compensation
$1.6M+ base
Richard Manchur, his son, president of Kettering Health Dayton from 2019 $830,952
Jared Keresoma, his son-in-law, vice president of operations, Greene Memorial Hospital $419,435

Manchur's base pay ran between $1.2 million and $1.5 million from 2015 to 2020, with bonuses typically between $390,000 and $465,000. His largest reported year was 2017, when total compensation exceeded $5 million, including more than $3.4 million in other reportable compensation.

Both whistleblower complaints raise the appointment of Richard Manchur as president of Kettering Health Dayton, alleging it did not go through board approval. He was replaced in August 2023, eight months after his father retired; the network said he left to pursue other opportunities.

The house on Stonebridge Road

This is the single most concrete document trail in the story, and it predates everything else by more than a decade.

On 1 April 2008, Kettering Medical Center signed a purchase agreement to buy a historic house on Stonebridge Road, directly behind the hospital campus, for $1 million, subject to board approval. The agreement was signed by the hospital's then chief financial officer, Russ Wetherell. The seller did not sign it.

Six weeks later, on 16 May 2008, Fred Manchur — then president of Kettering Medical Center — and his wife bought the same house themselves for $1 million. The seller also gave them $43,361 for repairs. Whether the board ever discussed or voted on the hospital's own proposed purchase is not known; when the Dayton Daily News asked in 2023, a network spokeswoman said she could provide no information.

The Manchurs still own the property. It runs to more than 15,000 square feet and the county auditor now values it at roughly $2.5 million. Decorations for the house appear among the expenditures the 2023 audit flagged as improper.

The pushback

Kettering Health's own framing has been notably protective of most of the 46. The network says several people were led to believe the trips, meals and gifts were legitimate business activity or acceptable presents, and had no reason to think otherwise until the investigation concluded and they were notified. It says the large majority chose to repay.

Wally Sackett, a former Kettering Health president who left the organization in October 2022, went further in public. He argued that reading the tax filings as a record of misuse of funds should be applied narrowly, and said most people on the list, himself included, did what they could to correct the discrepancies once identified. He also made a structural point worth taking seriously: an outside firm brought in to conduct a forensic audit may scrutinise costs in ways the network's own compliance and audit committees never had, and executives would not have known those concerns existed until they were raised.

That distinction is real. A list of 46 names is not a list of 46 wrongdoers. The filings themselves separate those who corrected from those who did not, and the Manchurs sit at the top of the second group. Andrea Jakobsons, whose family's travel appears among the flagged transactions, declined to comment.

The church dimension

What makes this more than a regional hospital story is the governance structure behind it. Adventist health systems in the United States seat denominational officers on their boards, and Kettering Health is no exception. Dave Weigley chaired the Kettering Health board while serving as president of the Columbia Union Conference — the same church body whose leaders appear on the recipient list alongside Ohio Conference officers and a North American Division officer.

The chair of a charity's board is the person whose job is to catch exactly this.

The people responsible for supervising the money were, in several cases, the people receiving it.

The internal accountability was thin. Weigley announced Manchur's interim replacement, then left the board in January 2023, saying at the time that he was stepping down because of his wife's illness. Roy Chew, a board member who had written a warm public tribute to Manchur on his retirement, was appointed to lead the search for his successor. More than a hundred current and former employees signed that same tribute board.

The Columbia Union issued a statement in March 2023 saying Kettering Health had made clear that issues identified through the investigation were being addressed immediately, and affirming its own commitment to accountable leadership and good stewardship. That was its last substantive public comment.

Weigley retired abruptly from the Columbia Union presidency on 1 March 2024. Marcellus T. Robinson, previously president of the Allegheny East Conference, was voted in by a special executive committee session that month and re-elected at the union's constituency meeting on 16 May 2026.

The second story: the 2025 ransomware attack

This is a separate matter from the money, and it was not concealed — it was impossible to conceal, because the hospitals stopped working. But it is the larger event by any measure of harm, and it is where Kettering Health currently faces the most legal exposure.

Patients whose data was compromised
1,695,382
Days attackers were inside the network before detection
41
Data exfiltrated, as claimed by the attackers
941 GB
Months the official victim count sat at a placeholder of 501
~9

What happened

The Interlock ransomware group entered Kettering Health's network on 9 April 2025 and was not detected until 20 May, when the system went down. Roughly 600 digital applications were shut off. Staff reverted to paper. Emergency departments diverted ambulances until 28 May. The Epic electronic health record came back on 2 June; the network declared normal operations restored on 10 June.

Kettering Health declined to pay, and Interlock published the stolen files. Beyond patient records, the trove by folder name appeared to include payroll records, employee files, scans of identity documents, security personnel files, Medicaid applications, pharmacy and blood bank records, corporate insurance and tax material and budget reports. This was not only a patient breach; the network's own staff were in it.

The compromised data includes names, addresses, dates of birth, Social Security numbers, taxpayer identification numbers, driver's licence and state ID numbers, passport numbers, medical record numbers, diagnosis and treatment information, insurance and billing information, financial account and card information, education records, and in some cases usernames with their associated passwords.

Who Interlock are

Interlock surfaced in September 2024 and has concentrated on healthcare, with DaVita, Texas Tech University Health Sciences Center and a US military supplier among its claimed victims. Researchers have noted similarities to the Rhysida ransomware family.

Its method matters for assessing fault. Interlock does not generally rely on phishing or exposed remote desktop. The FBI has documented drive-by downloads from compromised legitimate websites — unusual among ransomware crews — and ClickFix, in which a user is shown a fake CAPTCHA or error message and told to paste a command into the Windows Run box, making the victim the delivery mechanism. The group then deploys remote access trojans and tooling such as Cobalt Strike, and encrypts virtual machines across Windows and Linux, which is how a single well-placed action can take down an entire estate at once. Its ransom notes carry no initial demand or payment instructions.

One point of fairness: the joint FBI, CISA, HHS and MS-ISAC advisory on Interlock (AA25-203A) was published on 22 July 2025, two months after the Kettering attack. The network was not ignoring a specific federal warning about this group. It was, however, a healthcare organization in a year when healthcare was the sector Interlock was known to be working through.

The people it happened to

Local television followed individual patients from the first week, which is why this part of the record is unusually well documented.

Doris Roberts of Clayton had been diagnosed with stage 4 pancreatic cancer in April 2025. She had received one chemotherapy treatment. The second was cancelled by phone the day before the attack became public, and she spent the following weeks waiting for a call, saying her fear was that the cells were spreading while she waited. Her treatment resumed after about two weeks. She later joined the litigation, saying her main concern by then was that nobody file insurance claims in her name.

Lealon Mitchell told reporters in the first days that his wife's heart was barely functioning and her scheduled surgery had been delayed, with no clarity on when it would happen.

Mishelle Holder of Dayton is the lead plaintiff in the mass tort series. Her claim concerns a surgery on a blocked artery in her left leg and the pain she says followed.

The notification gap

This is the sharpest criticism available, and it holds up.

The breach was reported to the federal Office for Civil Rights on 21 July 2025 with a placeholder figure of at least 501 affected individuals. Kettering Health did not confirm the categories of compromised data until October 2025. Individual notification letters did not reach patients until around February 2026. The real figure of 1,695,382 did not appear on the federal portal until roughly April 2026.

That is about nine months before people were told their Social Security and passport numbers were exposed, and eleven months before the scale was public — all of it running after the attackers had already published the files in June 2025. The exposure was live the entire time the number sat at 501.

Kettering Health's own account is that the file review genuinely took that long, which is a common and not unreasonable explanation in breaches of this size. The counter-argument, which the plaintiffs are making, is that the data was already published and the delay ran entirely against the people whose information was in it.

The litigation

Two tracks, with different mechanics.

The first is a conventional data-breach class action in Montgomery County Common Pleas Court, alleging the network understood the risk of a breach, failed to protect patient data, and did not meet regulatory guidance or industry-standard practice.

The second is unusual and is the one to watch: mass tort personal injury claims over care that did not happen. These are individual claims rather than a class, which means individualised damages and the possibility of different outcomes case by case. Attorneys Michael Wright and Richard Schulte of Wright & Schulte say they have filed more than 200 care-related suits and represent more than 500 further people over stolen data. Forty-four were consolidated under a master complaint before Judge Angelina Jackson, originating from a personal injury filing in October 2025. Of those 44, 37 allege delayed treatment, 8 allege outright denial of care, and one alleges both, across more than fifteen Kettering Health locations. The master complaint pleads negligence, gross negligence, emotional distress, breach of contract and claims against unidentified parties. Plaintiffs seek compensatory damages over $25,000, punitive damages and fees, and a jury trial.

The plaintiffs' central allegation is not that Kettering Health was breached. It is that it had no adequate plan for a foreseeable cyberattack, and that when the systems went down it stopped seeing patients rather than falling back on a functioning manual process.

Kettering Health does not comment on pending litigation. Its public position, stated in its own incident FAQ, is that external partners and internal teams removed all threats, that network segmentation, enhanced monitoring and updated access controls are in place, and that it is confident its cybersecurity framework and employee security training are sufficient to mitigate future risks. That last sentence is the kind of statement plaintiffs' counsel tends to read back to a jury.

As of the end of August 2026 there is no reported settlement in either track, and no announced enforcement action by the HHS Office for Civil Rights. An OCR breach report is not an OCR investigation finding, and the portal entry does not by itself indicate any determination of fault.

What has been withheld

Kettering Health has not been silent, but it has been consistently selective. The following are matters on which it has declined to answer, all documented in contemporaneous reporting.

Add to that the amendment of its own statement from "senior executives and board members" to "individuals," and the eleven-month gap before the real breach figure was filed, and there is a discernible pattern: disclosure that is accurate as far as it goes, and goes no further than it has to.

What doesn't hold up

Some things that circulate about Kettering Health do not survive checking, and a page like this is worth less if it does not say so.

Where it stands

The Ohio attorney general's office opened its investigation into alleged inappropriate expenditure of charitable funds by Kettering Health executives and board members in 2021. It is still open.

Ohio's charitable law requires that such investigations stay confidential until charges are filed, which is why successive attorneys general have said almost nothing. Dave Yost said in March 2026 that he could neither confirm nor deny an investigation but expected to be able to say more later in the year; he left office in June. His successor, Andy Wilson, sworn in on 5 June 2026, was asked for an update in August and said they were "not there yet," adding that the office would put the information out when the time came.

Most recent public statement from the Ohio attorney general's office. No charges filed. Investigation confirmed ongoing.

The clock is the live problem. Misuse of nonprofit funds in Ohio is generally prosecuted under misappropriation or fraud statutes, which commonly run four years from discovery, though various circumstances can extend that. The complaints were filed in 2021. The forensic audit finished in 2023. Van Nostrand has said publicly that the reporting has barely scratched the surface, that it is frustrating to watch the limitation period likely run out, and has asked the attorney general, in as many words, to do something.

Timeline

Fred Manchur becomes president of Kettering Medical Center after twenty years with Adventist Health in California.

Kettering Medical Center signs an agreement to buy a house on Stonebridge Road for $1 million, pending board approval. Six weeks later the Manchurs buy it themselves.

Manchur is named chief executive.

The Dayton Daily News reports the network employs executives' relatives more often than other local health systems.

An anonymous letter from self-identified concerned Adventist church members circulates to staff, church officials and government officials.

Lori Van Nostrand files a complaint with the Ohio attorney general's office.

Kettering Health's board opens an internal investigation. The attorney general's office opens its own.

Van Nostrand resigns from Soin Medical Center, alleging retaliation. She later files with the Ohio Civil Rights Commission.

Manchur's retirement is announced, effective 21 December, with a leave of absence beforehand. No successor is named for six days.

Manchur retires. Chief financial officer Michael Mewhirter becomes interim chief executive. Spectrum publishes the first reporting on governance questions.

Dave Weigley leaves the Kettering Health board, citing his wife's illness. Celeste Ryan Blyden becomes chair.

A further anonymous complaint is sent to Attorney General Yost.

WHIO-TV obtains the complaints through a public records request. Kettering Health confirms it has hired outside firms, and says the allegations do not involve its Foundation.

The Dayton Daily News publishes the Stonebridge Road purchase documents.

Michael Gentry, formerly of Sentara Healthcare and AdventHealth, takes over as chief executive.

Richard Manchur is replaced as president of Kettering Health Dayton. Several other senior figures depart.

Gentry tells staff the investigation found organizational funds used for non-business purposes. No names, no figures.

Kettering Health reports the excess benefits to the IRS in amended tax filings.

Weigley retires abruptly as Columbia Union president. Marcellus T. Robinson is voted in.

The Interlock ransomware group enters Kettering Health's network. It goes undetected for 41 days.

Systems collapse. Around 600 applications go offline, staff revert to paper, emergency departments divert ambulances.

The breach is reported to federal regulators using a placeholder estimate of 501 people.

Kettering Health confirms what categories of patient data were taken. The count is still unresolved.

The Dayton Daily News publishes the amended filings: 46 people, more than $3.2 million, the Manchurs at the top and recorded as having repaid nothing.

Forty-four cyberattack suits are consolidated before Judge Angelina Jackson. The firm says more than 200 have been filed for roughly 700 people.

The federal breach portal is finally updated: 1,695,382 individuals affected.

Attorney General Dave Yost leaves office. Andy Wilson is sworn in and inherits the case.

Wilson declines to give details. Still no charges, five years after the first complaint.

Who's who

Fred Manchur

Chief executive, Kettering Health, 2010–2022; president of Kettering Medical Center from 2001

Named in whistleblower complaints as a central figure. He and his wife top the excess-benefits list at roughly $1.5 million and are recorded as having repaid nothing. He has not responded to press requests for comment. He has not been charged.

Dave Weigley

Kettering Health board chair; president, Columbia Union Conference, 2006–2024

Named alongside Manchur in the complaints. He and his wife appear on the list at roughly $293,000. Left the board in January 2023 citing his wife's illness, and retired from the union presidency in March 2024. He has not been charged.

Richard Manchur

President, Kettering Health Dayton, 2019–2023

Fred Manchur's son. Reported at $830,952 in 2021 compensation. Complaints allege his appointment bypassed the board. Left in August 2023; the network said he departed to pursue other opportunities. He has not been accused of receiving improper benefits.

Michael Gentry

Chief executive, Kettering Health, from July 2023

Arrived after the events under investigation. Announced the internal findings to staff, the decision to pursue repayment and refer information to authorities, and led the response to the 2025 cyberattack.

Lori Van Nostrand

Former executive secretary, Soin Medical Center; whistleblower

The only complainant to have put her name to a filing publicly. Says she was retaliated against and resigned in 2022. Has criticised the pace of the state investigation and says more remains uncovered.

Jim Londis

Corporate integrity officer, Kettering Health Network, 1998–2008

States that no comparable complaint was filed during his decade in the role.

Andy Wilson

Ohio attorney general, from June 2026

Inherited the investigation from Dave Yost. Bound by state confidentiality law and has declined to characterise its status beyond saying it is not yet at a point he can discuss.

The open questions

Sources

Everything on this page is drawn from the following published reporting and public documents. Where an allegation is unproven, it is identified as such above.

  1. Tax docs: Kettering Health execs, church leaders got $3.2M in improper benefits — Dayton Daily News, 18 January 2026
  2. Kettering Health misuse of funds: key takeaways — Dayton Daily News, January 2026
  3. Former Kettering Health whistleblower: 'Mr. Attorney General, do something' — Dayton Daily News, January 2026
  4. Former Kettering Health president says there's more nuance to 'excess benefits' — Dayton Daily News, January 2026
  5. Documents: Kettering health network played role in purchase, repair of Manchur mansion — Dayton Daily News, June 2023
  6. Internal investigation at Kettering Health yields findings of impropriety — Dayton Daily News, November 2023
  7. Ohio AG: state investigation into Kettering Health 'not there yet' — Journal-News / Dayton Daily News, 19 August 2026
  8. Kettering Health faces hundreds of lawsuits stemming from 2025 cyberattack — Dayton Daily News, March 2026
  9. Complaints with Ohio AG accuse former Kettering Health CEO of abusing charitable funds — WHIO-TV I-Team, March 2023
  10. Internal investigation finds inappropriate spending at Kettering Health — WHIO-TV I-Team, November 2023
  11. Kettering Health CEO departs, leaving governance questions — Spectrum Magazine, December 2022
  12. Former Kettering Health leaders accused of financial misuse — Spectrum Magazine, March 2023
  13. Kettering Health confirms misuse of funds at admin and board level — Spectrum Magazine, November 2023
  14. Columbia Union addresses next step after president's abrupt retirement — Spectrum Magazine, March 2024
  15. Statement of the Columbia Union Conference regarding allegations at Kettering Health — Columbia Union Visitor, March 2023
  16. Denominational workers and Kettering executives got $3.2 million in 'excess benefits' — Adventist Today, January 2026
  17. Interview with Dayton Daily News investigations editor Josh Sweigart — WYSO, 21 January 2026
  18. Kettering Health ransomware attack: running timeline and breach figures — HIPAA Journal, updated April 2026
  19. Kettering Health sued over disrupted care caused by 2025 data breach — WDTN, March 2026
  20. Class action brought against Kettering Health over stolen patient records — American Bar Association, June 2025
  21. Ohio system shakes up leadership — Becker's Hospital Review, August 2023
  22. Ohio Revised Code § 109.28 — confidentiality of charitable investigations