Medical software company database may have exposed tens of thousands of health records and PII


- A breach has impacted thousands of Carolina Anesthesiology PA patients
- Sensitive health information and patient data was exposed
- This leaves anyone affected at risk of identity theft or social engineering
Security researcher Jeremiah Fowler has discovered a non password-protected database, believed to be owned by Carolina Anesthesiology PA – a healthcare firm based out of North Carolina. This dataset contained 21,344 records, was almost 7GB, and spanned multiple states.
The information contained sensitive data, including patient information like names, physical addresses, phone numbers, and email addresses, as well as insurance coverage details, anesthesia summaries, diagnoses, family medical histories, and doctors notes. According to the researcher, there were files marked ‘Billing and Compliance Reports’, which gives an idea of the type of data included.
While there is so far no evidence to suggest the database fell into malicious hands, the potential compromise of the unprotected database could put many at risk of social engineering attacks like phishing, identity theft, or fraud.
Database on show
The researcher outlines that the dataset contained a “detailed analysis and key metrics related to medical billing and healthcare services provided” – but that, when contacted, the healthcare firm indicated that it did not own or manage the database, but that the owner has been notified and public access restricted.
It’s not clear if the information was accessed by a threat actor or third party, as only an internal audit would show this – and as far as we know, the information has not appeared on any dark web sites for sale by cybercriminals. Investigation by the researcher indicate that this folder’s contents was likely affiliated with Atrium Health – a partner of Carolina Anesthesiology PA.
“Our cyber security team immediately launched an internal investigation upon receiving an email tip in mid-February 2025 about a possible data breach. Our investigation found that Carolina Anesthesiology, P.A., who regularly provides anesthesia services at select facilities, misconfigured the technology service used for billing data, exposing some of their patient data,” said Atrium Health in response to the breach.
“We immediately shut down all data feeds to Carolina Anesthesiology and, as a courtesy, notified the regular governing entities. We continue to learn more from the Carolina Anesthesiology team about their plan to notify their patients of this breach. All data feeds remain off until this issue has been satisfactorily addressed.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
You might also like
A breach has impacted thousands of Carolina Anesthesiology PA patients Sensitive health information and patient data was exposed This leaves anyone affected at risk of identity theft or social engineering Security researcher Jeremiah Fowler has discovered a non password-protected database, believed to be owned by Carolina Anesthesiology PA – a…
Recent Posts
- The AI-powered future of ransomware is coming soon – here’s what we need to look out for
- Google’s customizable Gemini chatbots are now in Docs, Sheets, and Gmail
- Cisco warns of a serious security flaw in comms platform – and that it needs patching immediately
- From centralized to distributed: why cloud architecture had to change
- Hydrow Discount Code: Save Up to $150 in July
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021