Everest gang dumped Pacific Pulmonary Medical Group patient records

Organization
Pacific Pulmonary Medical Group
Exploit
Credential Compromise
Industry
Healthcare

Pacific Pulmonary Medical Group, a Riverside, California practice covering pulmonary medicine, critical care, thoracic surgery and sleep disorders, was added to the Everest extortion group's dark web leak site on October 25, 2024, and patient files were subsequently dumped there.

According to reporting on the dumped material, the files spanned 2021 to 2024 and included more than 150 images of patients' primary and secondary insurance cards and, in some cases, driver's licenses. Other records held names, contact details, dates of birth, Social Security numbers, demographic details, smoking status and emergency contacts, alongside patient identifiers, appointment records, referring physician names, insurance account data and billing information. The practice had not commented publicly when the leak was first written up in November 2024.

Pacific Pulmonary later filed a breach notice with the California attorney general and began sending notification letters and emails on January 3, 2025. In that account, the practice said an employee's login credentials for a third party scheduling application had been compromised, and that an unauthorized party had access between October 21 and October 22, 2024, the day the compromise was discovered.

The practice offered affected individuals complimentary credit monitoring through TransUnion, with enrolment required within 90 days of the notification letter. It did not publish a figure for how many people were involved.

Sources