🚨🏥 Threat actor DragonForce has claimed a new healthcare-sector extortion hit involving ouradvancedhealth[.]com. The listing claims the group obtained 2.3 million lines of "full patient data," along with partner agreements, management files, payroll records, and HR files.
After deduplication across 179 patient files, the dataset resolves to almost 2 million unique patient records, including minors. Folder NetData/ also contains eClinicalWorks artifacts, and Departments/Payor Contracting holds carrier contracts with major insurers.
DragonForce told us they gained access through a vulnerable remote monitoring and management tool that was exposed.
The actor also posted a timed pressure tactic, claiming it will leak 1,000 lines of patient data per day until it is paid or the countdown expires.
A file tree linked to the alleged exfil suggests the scope is far broader than a single clinic. The folder PatientData/ contains roughly 200 subdirectories, one per medical practice.
We have not verified the entirety of the stolen-data claim, reviewed the alleged sample, or confirmed the incident with the victim organization. Public records for ouradvancedhealth[.]com point to AdvancedHEALTH in Nashville, Tennessee, while the ransomware listing names Advanced Medical Consultants.
If confirmed, the incident would represent a significant healthcare data exposure with possible patient privacy, payroll, HR, and partner-contract impact, and likely federal HIPAA and state-level reporting obligations given the volume of minor records.