DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Prosthetic & Orthotic Care patient info remains publicly exposed

Posted on August 26, 2016 by Dissent

First, a quick update on the Athens Orthopedic Clinic breach:

It took two requests, but I’m pleased to report that Pastebin removed three pastes with over 1,350 patients’ information. Those pastes were separate from an earlier paste with an additional 500 patients’ information. News outlets that continue to report that 500 patients’ information was exposed and put up for sale are, to be blunt, reporting inaccurately.  Every AOC patient’s’ data was up for sale on the dark web, and the hackers claimed to have sold some of it (a claim that this site has no way of confirming or disputing). In addition, almost 2,000 AOC patients had their information on an easily accessed public site (Pastebin) where anyone could view it and copy it. For those unfamiliar with these things, Pastebin is on the web, not the dark web.

Following publication of my article that their patient data was still exposed on Pastebin,  AOC did not contact this site to ask where the data could be found so that they could take steps to get it removed. Nor did they contact this site to say thank-you for this site’s efforts to get THEIR patients’ information out of public view. Just so you know.

But today, in going through my notes, I realized that there’s still another paste up on Pastebin from another victim of TheDarkOverlord. This paste has data that appears to be from 499 patients of Prosthetic & Orthotic Care. 

On July 9, I had reported on the P&O breach.  In my report, I noted that I had made several attempts to notify them and speak to them, but they had not responded constructively. I even noted:

As of yesterday, some of their patients’ data had been dumped on a public paste site, and then there were those pictures…

P&O Care never got back to me. And like Athens Orthopedic Clinic, P&O Care never even asked me for the urls of any paste I had discovered. Maybe if they had contacted me or asked, they could have had the paste removed. Instead, it has been online since July 9 and has been viewed 181 times. There are 499 records in that paste with names, addresses, telephone numbers, insurance information, treatment codes, Social Security numbers (embedded in Medicare numbers), and more. The extent of information varies across patients, but it’s enough to cause problems.

DataBreaches.net has today submitted a request to Pastebin seeking removal of this paste, but seriously, getting these pastes removed is the responsibility of the breached clinics – not this site.

Update Aug. 28: The data are still publicly available.

Update Aug. 30: The data are still publicly available and I’ve sent a second request to Pastebin to remove it. I had also notified the clinic the other day, but once again, they did not respond. The paste has now been viewed 186 times.

Update Aug. 31: And finally, it’s gone.

Category: Commentaries and AnalysesHealth DataOf NoteU.S.

Post navigation

← Director at Citizens in Ohio Resigns Over Email Server Dispute
Opera server breach incident →

3 thoughts on “Prosthetic & Orthotic Care patient info remains publicly exposed”

  1. Justin Shafer says:
    August 27, 2016 at 12:29 am

    Good work.

  2. Alina Mughal says:
    August 27, 2016 at 6:56 am

    Thanks God you give us some information about such patients

  3. looeeznga says:
    August 29, 2016 at 11:41 am

    I wasn’t an AOC patient or client of any kind, but on behalf of the thousands of patients they have left in the dark from the beginning, THANK YOU…Seriously. THANK YOU, Dissent, for turning on the light and using your own time in alerting the general public about the extensiveness of the breach, your own dedication in getting the pastes removed, and your own human decency in being honest about what these folks can do in protecting themselves from possible credit and ID tarnishing established not by their own hands in the near to distant future.

    We need more like you in this world. Thank you.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.