Pulmonary Physicians of South Florida Clinics 2025 Data Breach

Pulmonary Physicians of South Florida Breach (2025): Patient Medical Diagnoses & Contact Records Exposed

Healthcare provider · Pulmonary and respiratory care · Specialty clinic network · USA

Pulmonary Physicians of South Florida Breach (2025): Patient Medical Diagnoses & Contact Records Exposed

Pulmonary healthcare provider.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
2KRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
PHI / MedicalMedical Diagnosis; Medication
AddressPhysical address
Classification Tags
Brain CipherRansomware / ExtortionHealthcareMedical2025

Breach Summary

In early 2025, Pulmonary Physicians of South Florida, a Miami-Dade pulmonary, critical-care, and sleep-medicine group, was hit by the BrainCipher ransomware group, which listed it on its dark-web leak site around February 19, 2025 with proof including a patient medication request and folders named with patient names and dates of birth. A DataBreach.com parse estimated about 2,028 records including names, addresses, phone numbers, emails, dates of birth, diagnoses, and medication information. The clinic had not publicly confirmed the breach as of the latest reporting.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

2K records analyzed

About Pulmonary Physicians of South Florida Clinics

Pulmonary Physicians of South Florida is a specialty medical group providing pulmonary, critical-care, and sleep-medicine services across hospitals in Miami-Dade and select Broward and Monroe county facilities. It maintains patient identity, contact, insurance, billing, and respiratory-treatment records.

Why They Hold Your Data

Pulmonary clinic networks collect patient identity, contact, insurance, billing, appointment, and treatment records across respiratory and specialty care workflows.

Recent Developments

The BrainCipher ransomware group listed the practice on its leak site in February 2025 with proof including a patient medication request and folders labeled with patient names and dates of birth. The clinic had not publicly confirmed the incident as of the latest reporting; class-action investigations were opened.

Data Points Exposed

7 verified field types
Date of Birth High
Email Address
Full Name
Medical Diagnosis Critical
Medication High
Phone Number
Physical address High

Breach Impact

Though the affected count is small (about 2,028), the exposure ties named patients to respiratory and sleep-medicine care and includes diagnoses and medication information, revealing chronic-illness or disability status. That creates medical-identity-fraud, extortion, and privacy risks and enables convincing treatment-themed scams, compounded by the clinic’s lack of public confirmation.

Exploitation & Downstream Threats

• Medical identity fraud and insurance abuse using diagnosis and medication data | • Extortion or embarrassment tied to respiratory/sleep conditions | • Identity verification bypass using name + date of birth | • Targeted phishing and vishing referencing pulmonary care | • Doxxing and physical targeting from exposed home addresses

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
BC
Threat Actor: Brain CipherConfidence: High
Ransomware group

Motivation: Financial extortion
A ransomware operation that emerged in 2024 and uses payloads based on LockBit 3.0. It operates a leak site and uses multi-pronged extortion.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation