PrivacySignal
Breach

Time’s Up: Ransomware Group Claims 150,000+ Cardiology Patient Records. We’ve Seen the Data.

DataBreaches.net · · International · Data Breaches

A ransomware group called Orova claims to have stolen more than 150,000 patient records from Cardiology Associates of Port Huron, a Michigan cardiology practice operating across nine locations. Journalists have reviewed the data, which reportedly contains personally identifiable and protected health information.

Why this matters: Cardiology patients do not just hand over names and addresses. They share diagnoses, test results, medications, and the kind of intimate health details that follow people for life. More than 150,000 of them may now have that information sitting on a criminal leak site. Medical data is especially hard to take back once it is out. The practice has nine locations, so the exposure is spread across a wide community. The people most affected had no say in how their records were protected, and right now they likely do not even know this happened.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
DataBreaches.net · · International

A rough day at the extortion office and a botched attack on Blossom Health.

An apparent extortionist targeted Blossom Health, a US telehealth and psychiatry platform, by compromising either the platform itself or an individual provider's account and sending what appears to be a ransom demand. The incident came to light after a patient contacted DataBreaches directly to report it.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

A massive cache of Valve data has reportedly leaked online, appearing to include Portal 2’s elusive beta build and a potential weapon from Half-Life 2: Episode 3

A large cache of internal Valve data, reportedly totaling 12 terabytes, has leaked from an unknown source and is being analyzed online. The files appear to include unreleased beta builds of several classic Valve games and possible content from the long-cancelled Half-Life 2: Episode 3.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

VT: Local VA warns of possible data breach

The VA's White River Junction, Vermont healthcare facility disclosed that unencrypted communications containing veterans' personal health information were sent in error earlier this summer. The department acknowledged the incident in a public release, confirming the exposure was unintentional.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy Read original →
Breach
DataBreaches.net · · International

De: Hackers demand 30 bitcoin from Berlin as sensitive data breach widens

Hackers have demanded 30 bitcoin from the Berlin city government following a breach of its administrative data network, with the attack occurring roughly two weeks ago. Berlin officials are declining to disclose what data was accessed, who is responsible, or how they are responding to the ransom demand.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · AI governance

#breach#gdpr Read original →
Breach
DataBreaches.net · · International

US officials backpedal on claims that government agencies were hacked by Chinese

U.S. officials have walked back earlier statements claiming Chinese spies successfully hacked several government agencies, clarifying that the Senate, the Federal Reserve, NASA, and others were targeted but not confirmed as breached. The Justice Department quietly updated its language to reflect the distinction.

Who should care: Cybersecurity · Privacy officers · Administrators