Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Data Breach

Health Risk: How a Medical Practice Exposed Details for 40,000 Patients

Cyberinchief by Cyberinchief
October 23, 2025
Reading Time: 4 mins read
0
Health Risk: How a Medical Practice Exposed Details for 40,000 Patients


RELATED POSTS

UK Hospital Asks Court to Stymie Ransomware Data Leak

These five countries recorded the most third-party data breaches last year

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

While this blog post provides a description of a data exposure discovery involving Cohen Bergman Klepper Romano Mds PC, this is no longer an active data breach. As soon as the UpGuard Cyber Risk Team notified Accenture of this publicly exposed information, immediate action was taken, securing the open buckets and preventing further access.  

The UpGuard Cyber Risk Team can now confirm that a digital data repository containing records from a Long Island medical practice was left publicly accessible, revealing medical details and personally identifiable information (PII) for over forty-two thousand patients. As detailed here and at databreaches.net, this data exposure appears to originate from Cohen Bergman Klepper Romano Mds PC, a Huntington, New York practice specializing in internal medicine and cardiovascular health, revealing such details as patient names, Social Security numbers, dates of birth, phone numbers, insurance information, and more. 

The presence of physicians’ personal information in the files, such as their Social Security numbers and addresses, as well as over three million “medical notes,” each one a physician’s observation of a patient – such as a blood pressure measurement or a comment about a patient’s reflexes – further widens the exposure’s reach. This incident highlights the importance of securing digital assets which could result in the leak of protected medical information, particularly for smaller organizations like medical practices that generate such sensitive data.

The Discovery

On January 25th, 2018, UpGuard Director of Cyber Risk Research Chris Vickery discovered an exposed port within IT systems containing data involving the medical office. The exposed port in question, port 873, is typically used for rsync, or “remote synchronization,” a utility typically used to copy data from one machine to another.

While rsync can be secured against public access by employing the utility’s “hosts allow/deny” functions, it can also be configured for global access, allowing anyone to access the information knowing only the server’s IP address.  In this case, lacking the protection provided by a directive to only allow particular IP addresses to access the rsync server, the repository was exposed to anyone who happened across it.

Revealed within were two sections titled “backupwscohen” and “backupsrvcohen.” Of the two partitioned areas, only “backupwscohen” was configured to be publicly accessible. Contained in this area are a number of files containing sensitive data. One of them is an Outlook backup saved as a .pst file, containing a large number of apparent email communications, while a virtual hard drive stored within the repository holds a number of documents about office staff. Staff home addresses, spousal details, and even the names of their children are revealed, and in at least one instance, the Social Security numbers for all family members.

Buy JNews
ADVERTISEMENT

A folder titled “TPSData” contains the largest amount of patient information, stored in a database across a number of tables. One table, titled “pracperson,” contains over forty-two thousand names. Taken together, the tables reveal Social Security numbers, dates of birth, phone numbers, email addresses, ethnicities, and insurance policy information. Perhaps most troubling is the presence in one table of over three million medical notes – each one a specific observation of an individual’s condition.

The Significance

The exposure of personally identifiable information about tens of thousands of individuals raises serious questions about how privileged medical information is secured on digital systems. While HIPAA regulations mandate the secure storage of patient records, PII, and medical information, this leak provides a vivid example of how easily such requirements can go unmet if technical errors go uncorrected.

Redacted image of “Person” data including LastName, FirstName, MiddleName, NameSuffix, SortName, SSN, Sex, DOB, Race, Language, MaritalStatus, HomePhone, Email, EmploymentStatus, SoundEx, HeadOfHouseholdID, RelationToHeadOfHouse, and more.

Screen Shot 2018-03-25 at 3.23.04 PM.png

Redacted image of “Policy” data including Server_id, PlanID, PolicyNumber, Class, GroupNumber, SubscriberID, AssignBenefits, Description, StartDate, EndDate, TimeStamp, Last User, CreateStamp, Create User, AuthorizePayment.

Beyond the obvious sensitivity of any exposure of an individual’s medical background, the leak of patient – and doctor – Social Security numbers, in association with personal details like home address, insurance information, and date of birth, provide ample ammunition for fraudsters. Armed with the contact information for patients, and the knowledge of which doctor’s office they go to, malicious actors could also socially engineer exposed individuals, posing as a representative of the physicians to further extract sensitive information.

Screen Shot 2018-03-25 at 3.05.59 PM.png

Word document listing personnel and vendors with keys to the office.

Finally, while the exposure was eventually secured by March 19th, it would be over a month after initial analysis and notification on February 12th, and following many phone calls and emails in the interim, before the data was no longer accessible. The Cyber Risk Team’s repeated efforts to alert the affected clinic as to the importance of this exposure, and the prolonged exposure of this information despite this, speaks to the vital urgency of implementing a durable process for use in acknowledging a breach disclosure and remediating the issue. Empowering personnel with directions on how to respond to news of a data exposure protects both the enterprise and any individuals whose information may be leaking.



Source link

Tags: detailsExposedHealthMedicalPatientsPracticeRisk
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

UK Hospital Asks Court to Stymie Ransomware Data Leak
Data Breach

UK Hospital Asks Court to Stymie Ransomware Data Leak

December 8, 2025
These five countries recorded the most third-party data breaches last year
Data Breach

These five countries recorded the most third-party data breaches last year

December 8, 2025
LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net
Data Breach

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

December 7, 2025
Rethinking the CIO-CISO Dynamic in the Age of AI
Data Breach

Rethinking the CIO-CISO Dynamic in the Age of AI

December 6, 2025
NHS supplier hit with £3m fine for security failings that led to attack
Data Breach

NHS supplier hit with £3m fine for security failings that led to attack

December 6, 2025
HHS Outlines AI Road Map Amid Major Department Overhaul
Data Breach

HHS Outlines AI Road Map Amid Major Department Overhaul

December 5, 2025
Next Post
పిల్లల కిడ్నాప్ పేరుతో ఫోన్లు వస్తాయ్.. జాగ్రత్త !! | CP Sajjanar Tweet On Cyber Crime Alert |

పిల్లల కిడ్నాప్ పేరుతో ఫోన్లు వస్తాయ్.. జాగ్రత్త !! | CP Sajjanar Tweet On Cyber Crime Alert |

Exploring Cyber Security Tools: From Cheap DIY to High-Tech & The Future of AI in Cyber Security

Exploring Cyber Security Tools: From Cheap DIY to High-Tech & The Future of AI in Cyber Security

Recommended Stories

If you want to report Cyber crime but don’t want to share your personal details. #watchnow

If you want to report Cyber crime but don’t want to share your personal details. #watchnow

October 10, 2025
Cybercrime in the Age of AI, with Bogdan Botezatu

Cybercrime in the Age of AI, with Bogdan Botezatu

November 8, 2025
CYBER CRIME ONLINE COMPLAIN वापस कैसे ले…???HOW TO WITHDRAW CYBER CRIME COMPLAIN ONLINE …???

CYBER CRIME ONLINE COMPLAIN वापस कैसे ले…???HOW TO WITHDRAW CYBER CRIME COMPLAIN ONLINE …???

November 17, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested