Healthcare provider · Pulmonary and respiratory care · Specialty clinic network · USA
Pulmonary healthcare provider.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In early 2025, Pulmonary Physicians of South Florida, a Miami-Dade pulmonary, critical-care, and sleep-medicine group, was hit by the BrainCipher ransomware group, which listed it on its dark-web leak site around February 19, 2025 with proof including a patient medication request and folders named with patient names and dates of birth. A DataBreach.com parse estimated about 2,028 records including names, addresses, phone numbers, emails, dates of birth, diagnoses, and medication information. The clinic had not publicly confirmed the breach as of the latest reporting.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
2K records analyzed
Pulmonary Physicians of South Florida is a specialty medical group providing pulmonary, critical-care, and sleep-medicine services across hospitals in Miami-Dade and select Broward and Monroe county facilities. It maintains patient identity, contact, insurance, billing, and respiratory-treatment records.
Pulmonary clinic networks collect patient identity, contact, insurance, billing, appointment, and treatment records across respiratory and specialty care workflows.
The BrainCipher ransomware group listed the practice on its leak site in February 2025 with proof including a patient medication request and folders labeled with patient names and dates of birth. The clinic had not publicly confirmed the incident as of the latest reporting; class-action investigations were opened.
Though the affected count is small (about 2,028), the exposure ties named patients to respiratory and sleep-medicine care and includes diagnoses and medication information, revealing chronic-illness or disability status. That creates medical-identity-fraud, extortion, and privacy risks and enables convincing treatment-themed scams, compounded by the clinic’s lack of public confirmation.
• Medical identity fraud and insurance abuse using diagnosis and medication data | • Extortion or embarrassment tied to respiratory/sleep conditions | • Identity verification bypass using name + date of birth | • Targeted phishing and vishing referencing pulmonary care | • Doxxing and physical targeting from exposed home addresses
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware operation that emerged in 2024 and uses payloads based on LockBit 3.0. It operates a leak site and uses multi-pronged extortion.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation