
Over 8M patient records leaked in healthcare data breach
In the past decade, healthcare data has become one of the most sought-after targets in cybercrime. From insurers to clinics, every player in the ecosystem handles some form of sensitive information.
However, breaches do not always originate from hospitals or health apps. Increasingly, patient data is managed by third-party vendors offering digital services such as scheduling, billing and marketing.
One such breach at a digital marketing agency serving dental practices recently exposed approximately 2.7 million patient profiles and more than 8.8 million appointment records.
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide — free when you join.
Cybernews researchers have discovered a misconfigured MongoDB database exposing 2.7 million patient profiles and 8.8 million appointment records. The database was publicly accessible online, unprotected by passwords or authentication protocols. Anyone with basic knowledge of database scanning tools could have accessed it.
The exposed data included names, birthdates, addresses, emails, phone numbers, gender, chart IDs, language preferences and billing classifications. Appointment records also contained metadata such as timestamps and institutional identifiers.
Clues within the data structure point toward Gargle, a Utah-based company that builds websites and offers marketing tools for dental practices. While not a confirmed source, several internal references and system details suggest a strong connection. Gargle provides appointment scheduling, form submission and patient communication services. These functions require access to patient information, making the firm a likely link in the exposure.
After the issue was reported, the database was secured. The duration of the exposure remains unknown, and there is no public evidence indicating whether the data was downloaded by malicious actors before being locked down.
We reached out to Gargle for a comment but did not hear back before our deadline.
The exposed data presents a broad risk profile. On its own, a phone number or billing record might seem limited in scope. Combined, however, the dataset forms a complete profile that could be exploited for identity theft, insurance fraud and targeted phishing campaigns.
Medical identity theft allows attackers to impersonate patients and access services under a false identity. Victims often remain unaware until significant damage is done, ranging from incorrect medical records to unpaid bills in their names. The leak also opens the door to insurance fraud, with actors using institutional references and chart data to submit false claims.
This type of breach raises questions about compliance with the Health Insurance Portability and Accountability Act, which mandates strong security protections for entities handling patient data. Although Gargle is not a healthcare provider, its access to patient-facing infrastructure could place it under the scope of that regulation as a business associate.
If your information was part of the healthcare breach or any similar one, it's worth taking a few steps to protect yourself.
1. Consider identity theft protection services: Since the healthcare data breach exposed personal and financial information, it's crucial to stay proactive against identity theft. Identity theft protection services offer continuous monitoring of your credit reports, Social Security number and even the dark web to detect if your information is being misused. These services send you real-time alerts about suspicious activity, such as new credit inquiries or attempts to open accounts in your name, helping you act quickly before serious damage occurs. Beyond monitoring, many identity theft protection companies provide dedicated recovery specialists who assist you in resolving fraud issues, disputing unauthorized charges and restoring your identity if it's compromised. See my tips and best picks on how to protect yourself from identity theft.
2. Use personal data removal services: The healthcare data breach leaks loads of information about you, and all this could end up in the public domain, which essentially gives anyone an opportunity to scam you.
One proactive step is to consider personal data removal services, which specialize in continuously monitoring and removing your information from various online databases and websites. While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time. Check out my top picks for data removal services here.
Get a free scan to find out if your personal information is already out on the web
3. Have strong antivirus software: Hackers have people's email addresses and full names, which makes it easy for them to send you a phishing link that installs malware and steals all your data. These messages are socially engineered to catch them, and catching them is nearly impossible if you're not careful. However, you're not without defenses.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.
4. Enable two-factor authentication: While passwords weren't part of the data breach, you still need to enable two-factor authentication (2FA). It gives you an extra layer of security on all your important accounts, including email, banking and social media. 2FA requires you to provide a second piece of information, such as a code sent to your phone, in addition to your password when logging in. This makes it significantly harder for hackers to access your accounts, even if they have your password. Enabling 2FA can greatly reduce the risk of unauthorized access and protect your sensitive data.
5. Be wary of mailbox communications: Bad actors may also try to scam you through snail mail. The data leak gives them access to your address. They may impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions and security alerts.
If nothing else, this latest leak shows just how poorly patient data is being handled today. More and more, non-medical vendors are getting access to sensitive information without facing the same rules or oversight as hospitals and clinics. These third-party services are now a regular part of how patients book appointments, pay bills or fill out forms. But when something goes wrong, the fallout is just as serious. Even though the database was taken offline, the bigger problem hasn't gone away. Your data is only as safe as the least careful company that gets access to it.
Do you think healthcare companies are investing enough in their cybersecurity infrastructure? Let us know by writing us at Cyberguy.com/Contact
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Follow Kurt on his social channels
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


CBS News
12 minutes ago
- CBS News
Fenway concession workers vote to authorize strike over stalled contract negotiations
Workers who staff the concession stands at Boston's Fenway Park have voted to authorize a strike, but are continuing to work for now. What the vote means Local 26 said it has been trying to negotiate a deal with Fenway's food contractor - Aramark - since the first of the year. The union's contract expired on December 31, 2024. According to the union, 95% of workers voted to authorise a strike during Sunday's vote. However, the workers have not yet walked out. The workers include about 700 cashiers, cooks, beer sellers and souvenir vendors. What do workers want? The union said key issues in the negotiations include wages, technology and scheduling. The workers contend they make less than $20 per hour, which is less than the major league standard. "We love working at Fenway. My co-workers and regular Red Sox fans are like my second family. But workers are underpaid, and increased automation is taking away jobs and cutting into our earnings," said Natalie Greening, a beer seller who started at Fenway when she was in high school and has worked at the stadium for 20 years. The union cited Marlins Park in Miami as an example, claiming that workers at the stadium earn $2.73 more per hour while a beer at the Florida ballpark costs $5.65 less than at Fenway. "Boston is a union town, and it's time to bring all Fenway workers' wages up to standard," said Carlos Aramayo, president of UNITE HERE Local 26, which represents the Fenway workers. "Local 26 hotel workers fought for, and won, $10-an-hour raises last year, and Local 26 university dining workers will be making a minimum of $30 an hour by 2028. There's no reason for Fenway workers to be left behind. They deserve raises and respect!"
Yahoo
16 minutes ago
- Yahoo
Jim Cramer on Oklo: 'These Guys Are Serious Professionals'
Oklo Inc. (NYSE:OKLO) is one of the 16 stocks Jim Cramer recently discussed. Discussing the hype around nuclear stocks, Cramer said: 'What else fits the moment? We've become transfixed by nuclear power. We know that the data centers that seem to be going up everywhere are humongous users of electricity. We know that the hyperscalers who run the data centers would prefer to use nuclear power because it's clean. We know that we've been decommissioning nukes for decades because we thought they were unsafe. But one company, Oklo, never gave up hope that the nuclear industry could turn things around and has toiled for 12 years to get its form of nuclear power endorsed by our government. A close-up of a businessperson energetically pointing at an electronic stock chart. Oklo (NYSE:OKLO) designs and builds fission power plants that produce steady, large-scale energy. The company also handles services for recycling spent nuclear fuel. While we acknowledge the potential of OKLO as an investment, we believe certain AI stocks offer greater upside potential and carry less downside risk. If you're looking for an extremely undervalued AI stock that also stands to benefit significantly from Trump-era tariffs and the onshoring trend, see our free report on the best short-term AI stock. READ NEXT: The Best and Worst Dow Stocks for the Next 12 Months and 10 Unstoppable Stocks That Could Double Your Money. Disclosure: None. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data
Yahoo
16 minutes ago
- Yahoo
Insiders At Vistra Sold US$39m In Stock, Alluding To Potential Weakness
Over the past year, many Vistra Corp. (NYSE:VST) insiders sold a significant stake in the company which may have piqued investors' interest. Knowing whether insiders are buying is usually more helpful when evaluating insider transactions, as insider selling can have various explanations. However, when multiple insiders sell stock over a specific duration, shareholders should take notice as that could possibly be a red flag. While insider transactions are not the most important thing when it comes to long-term investing, logic dictates you should pay some attention to whether insiders are buying or selling shares. AI is about to change healthcare. These 20 stocks are working on everything from early diagnostics to drug discovery. The best part - they are all under $10bn in marketcap - there is still time to get in early. Notably, that recent sale by Scott Helm is the biggest insider sale of Vistra shares that we've seen in the last year. That means that even when the share price was slightly below the current price of US$174, an insider wanted to cash in some shares. When an insider sells below the current price, it suggests that they considered that lower price to be fair. That makes us wonder what they think of the (higher) recent valuation. However, while insider selling is sometimes discouraging, it's only a weak signal. This single sale was just 16% of Scott Helm's stake. In total, Vistra insiders sold more than they bought over the last year. The chart below shows insider transactions (by companies and individuals) over the last year. By clicking on the graph below, you can see the precise details of each insider transaction! View our latest analysis for Vistra If you like to buy stocks that insiders are buying, rather than selling, then you might just love this free list of companies. (Hint: Most of them are flying under the radar). Over the last three months, we've seen significant insider selling at Vistra. In total, insiders dumped US$22m worth of shares in that time, and we didn't record any purchases whatsoever. In light of this it's hard to argue that all the insiders think that the shares are a bargain. Another way to test the alignment between the leaders of a company and other shareholders is to look at how many shares they own. Usually, the higher the insider ownership, the more likely it is that insiders will be incentivised to build the company for the long term. It's great to see that Vistra insiders own 1.0% of the company, worth about US$576m. Most shareholders would be happy to see this sort of insider ownership, since it suggests that management incentives are well aligned with other shareholders. Insiders haven't bought Vistra stock in the last three months, but there was some selling. Despite some insider buying, the longer term picture doesn't make us feel much more positive. But it is good to see that Vistra is growing earnings. While insiders do own a lot of shares in the company (which is good), our analysis of their transactions doesn't make us feel confident about the company. So while it's helpful to know what insiders are doing in terms of buying or selling, it's also helpful to know the risks that a particular company is facing. To assist with this, we've discovered 2 warning signs that you should run your eye over to get a better picture of Vistra. Of course Vistra may not be the best stock to buy. So you may wish to see this free collection of high quality companies. For the purposes of this article, insiders are those individuals who report their transactions to the relevant regulatory body. We currently account for open market transactions and private dispositions of direct interests only, but not derivative transactions or indirect interests. Have feedback on this article? Concerned about the content? Get in touch with us directly. Alternatively, email editorial-team (at) article by Simply Wall St is general in nature. We provide commentary based on historical data and analyst forecasts only using an unbiased methodology and our articles are not intended to be financial advice. It does not constitute a recommendation to buy or sell any stock, and does not take account of your objectives, or your financial situation. We aim to bring you long-term focused analysis driven by fundamental data. Note that our analysis may not factor in the latest price-sensitive company announcements or qualitative material. Simply Wall St has no position in any stocks mentioned. Sign in to access your portfolio