Medical software company database may have exposed tens of thousands of health records and PII
- A breach has impacted thousands of Carolina Anesthesiology PA patients
- Sensitive health information and patient data was exposed
- This leaves anyone affected at risk of identity theft or social engineering
Security researcher Jeremiah Fowler has discovered a non password-protected database, believed to be owned by Carolina Anesthesiology PA – a healthcare firm based out of North Carolina. This dataset contained 21,344 records, was almost 7GB, and spanned multiple states.
The information contained sensitive data, including patient information like names, physical addresses, phone numbers, and email addresses, as well as insurance coverage details, anesthesia summaries, diagnoses, family medical histories, and doctors notes. According to the researcher, there were files marked ‘Billing and Compliance Reports’, which gives an idea of the type of data included.
While there is so far no evidence to suggest the database fell into malicious hands, the potential compromise of the unprotected database could put many at risk of social engineering attacks like phishing, identity theft, or fraud.
Database on show
The researcher outlines that the dataset contained a “detailed analysis and key metrics related to medical billing and healthcare services provided” – but that, when contacted, the healthcare firm indicated that it did not own or manage the database, but that the owner has been notified and public access restricted.
It’s not clear if the information was accessed by a threat actor or third party, as only an internal audit would show this – and as far as we know, the information has not appeared on any dark web sites for sale by cybercriminals. Investigation by the researcher indicate that this folder’s contents was likely affiliated with Atrium Health – a partner of Carolina Anesthesiology PA.
“Our cyber security team immediately launched an internal investigation upon receiving an email tip in mid-February 2025 about a possible data breach. Our investigation found that Carolina Anesthesiology, P.A., who regularly provides anesthesia services at select facilities, misconfigured the technology service used for billing data, exposing some of their patient data,” said Atrium Health in response to the breach.
“We immediately shut down all data feeds to Carolina Anesthesiology and, as a courtesy, notified the regular governing entities. We continue to learn more from the Carolina Anesthesiology team about their plan to notify their patients of this breach. All data feeds remain off until this issue has been satisfactorily addressed.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
You might also like
A breach has impacted thousands of Carolina Anesthesiology PA patients Sensitive health information and patient data was exposed This leaves anyone affected at risk of identity theft or social engineering Security researcher Jeremiah Fowler has discovered a non password-protected database, believed to be owned by Carolina Anesthesiology PA – a…
Recent Posts
- The University of Cambridge says it successfully tested a vaccine with an AI-designed antigen
- MAHA wants to make cotton the new beef tallow
- What do you mean my new smart scale is ‘built for GLP-1 users’?
- What do you mean my new smart scale is ‘built for GLP-1 users’?
- Can AI tell if your script will make a hit film?
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023