In a post yesterday, I reported that protected health information and identity information of patients of Athens Orthopedic Clinic that had been leaked online by hackers remained available to anyone who knows where to look for it. Although it’s frustrating and understandably worrying to patients, I give AOC credit that they tried to find the leaks and plug them....
DataBreaches.net discovered today that two copies of a paste (data dump) with over 860 AOC patients’ information is still available online if you know where to look for it. I’m providing a redacted screenshot below so patients can get a sense of what these pastes/leaks look like, although I’ve blacked out most of the street addresses,...
At the end of June, DeepDotWeb broke the story that hackers calling themselves TheDarkOverlord (TDO) had put three databases with patient information up for sale on the dark net. Although the owners of the databases were not listed, DataBreaches.net was able to identify two of the three entities as the Athens Orthopedic Clinic (AOC) in Atlanta and Midwest Orthopedic Pain and Spine (MOPS) in Farmington, Missouri. Both...
Quick note to point out that three of TheDarkOverlord’s victims have reported their breaches to HHS, although the numbers they report do not always match what had been claimed by TDO and previously reported in the media: Midwest Orthopedic Pain and Spine reported that 29,153 patients (not 48,000) were affected; Athens Orthopedic Clinic reported that...
On June 26, DataBreaches.net reported that several databases with patient information had allegedly been hacked and put up for sale on the dark net by hackers calling themselves TheDarkOverlord (TDO). This site subsequently identified one of the entities as the Athens Orthopedic Clinic in Georgia, and contacted them to alert them that it appeared...
Another one of TheDarkOverlord’s targets has issued a statement about the hack and theft of their patient information. DataBreaches.net had identified this entity and first reported on the hack on July 9. Somewhat disturbingly, and as we have seen in other cases with the same parameters, Prosthetic & Orthotic Care (P&O Care) does not appear...
In the past 24 hours, two of TheDarkOverlord’s targets have publicly acknowledged breaches previously reported by this site. Yesterday, it was the Athens Orthopedic Clinic in Georgia who issued a public statement (previous coverage). Today, it’s a group of clinics in Farmington, Missouri (previous coverage). Daily Journal Online reports: The medical group which includes...
On June 26, this site reported that a database with almost 397,000 patient records was up for sale on the dark net. I subsequently tentatively identified the entity as Athens Orthopedic Clinic in Georgia, but they never officially confirmed that it was their data, noting only that they were investigating and had only first...
On July 12, the hacker known as “The Dark Overlord” (TDO) offered the source code, software signing keys, and customer license database for a firm that develops and markets software that among other things, implements the HL7 standards. The entity was not named in the listing on TheRealDeal Market. As I reported on July 12, I...
Athens Orthopedic Clinic incident response leaves patients in the dark and out of pocket for protection