DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Stormous claims to have protected health info on 600,000 patients of North Country Healthcare. The data appear fake.

Posted on July 13, 2025 by Dissent

North Country HealthCare is a federally qualified community health center that provides comprehensive medical services in 14 locations in 11 communities throughout Northern Arizona. Their services include family medicine, pediatrics, obstetrics and gynecology, dental care, behavioral health services, telemedicine, health screenings, and more. An April 2022 article about them reported that North Country served 55,000 patients annually.

Stormous listing. Description in text of article.

The threat actors known as “Stormous” claim to have exfiltrated data on 600,000 patients. They also claim that they will be leaking 100,000 patients’ records and selling the other 500,000. As of publication there is one day left on a countdown clock.

As proof of claims, Stormous leaked what they claimed are 11,684 records with patients’ name, clinic name, provider ID number, appointment date, address, type of health insurance, ICD-10 Code, treatment, date of birth, gender, contact, medical history, race/ethnicity, and insurance policy number.

Attempts to verify the data in the sample failed pretty spectacularly.

For many records, the gender was incorrect for the patient name, and for many records, DataBreaches could find no person with that name in the area of Arizona listed as the address. Although people may move away over the years, the dates of service were in 2022 and 2023, and one would expect that at least some people still resided at the same address or in the same area. But not only could the people not be found at the addresses listed or in that area, but many of the addresses could not be found at all during attempts to search for the addresses. A check of some of the phone numbers revealed area codes that were in Missouri, Washington State, and Jamaica — nowhere near the addresses listed.

DataBreaches emailed North Country HealthCare to inquire about the claimed breach and reached out to Stormous on Tox.

No replies were received by publication, but this post will be updated if more information becomes available. For now, DataBreaches is treating this claimed breach as a likely fake.

No related posts.

Category: Breach Incidents

Post navigation

← Back from the Brink: District Court Clears Air Regarding Individualized Damages Assessment in Data Breach Cases

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Stormous claims to have protected health info on 600,000 patients of North Country Healthcare. The data appear fake.
  • Back from the Brink: District Court Clears Air Regarding Individualized Damages Assessment in Data Breach Cases
  • Multiple lawsuits filed against Doyon Ltd over April 2024 data breach and late notification
  • Chinese hackers suspected in breach of powerful DC law firm
  • Qilin Emerged as The Most Active Group, Exploiting Unpatched Fortinet Vulnerabilities
  • CISA tags Citrix Bleed 2 as exploited, gives agencies a day to patch
  • McDonald’s McHire leak involving ‘123456’ admin password exposes 64 million applicant chat records
  • Qilin claims attack on Accu Reference Medical Laboratory. It wasn’t the lab’s first data breach.
  • Louis Vuitton hit by data breach in Türkiye, over 140,000 users exposed; UK customers also affected (1)
  • Infosys McCamish Systems Enters Consent Order with Vermont DFR Over Cyber Incident

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Australian law is now clearer about clinicians’ discretion to tell our patients’ relatives about their genetic risk
  • The ICO’s AI and biometrics strategy
  • Trump Border Czar Boasts ICE Can ‘Briefly Detain’ People Based On ‘Physical Appearance’
  • DeleteMyInfo Wins 2025 Digital Privacy Excellence Award from Internet Safety Council
  • TikTok Loses First Appeal Against £12.7M ICO Fine, Faces Second Investigation by DPC
  • German court offers EUR 5000 compensation for data breaches caused by Meta
  • How to Build on Washington’s “My Health, My Data” Act

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.