Sunflower Medical Group breach exposed data on nearly 221,000 patients
- Organization
- Sunflower Medical Group
- Exploit
- Ransomware
- Industry
- Healthcare
Sunflower Medical Group, a multi-specialty practice with care centers in Kansas City, Lenexa and Roeland Park, Kansas, disclosed that an intruder had been inside its network for more than three weeks over the winter. Staff identified suspicious activity on January 7, 2025, and a third-party forensic investigation established that unauthorized access ran from December 15, 2024 until the day it was detected.
The review confirmed that files had been copied from the network. Depending on the individual, the exposed information included names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical information and health insurance details. The practice notified 220,968 people.
The Rhysida ransomware group claimed the attack and listed Sunflower on its leak site, advertising a three terabyte SQL database and asserting that it held identity documents and Social Security numbers for around 400,000 people. The Register reported roughly 7.6 TB posted in total. Those figures were the gang's own claims and are well above the number Sunflower reported to regulators.
Sunflower said it had found no evidence that the stolen information had been misused. It offered affected patients complimentary credit monitoring and identity theft protection, and said it had put additional technical safeguards in place. The Register reported the credit monitoring offer as one year.