Healthcare provider · Gastroenterology and family medicine · Specialty clinic network · USA
Medical practice focused on digestive and family health care.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
On June 2, 2025, the Interlock ransomware group completed exfiltration of data from Texas Digestive Specialists (listed on its leak site as "Family Health Specialists") and deployed ransomware, after gaining a foothold in late May 2025. Interlock claimed roughly 263 GB across 215,245 files. The practice later confirmed the incident and notified approximately 41,521 individuals. Exposed data included names, addresses, dates of birth, Social Security numbers, medical records/diagnoses, and health insurance information. Third-party researchers downloaded sample data from the leak; the breach is catalogued by DataBreach.com and reported to HHS/state regulators.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
42K records analyzed
Texas Digestive Specialists (also operating as Family Health Specialists) is a multi-location gastroenterology and family-medicine practice serving the Rio Grande Valley in Texas, with clinics in McAllen, Brownsville, and Harlingen. It maintains patient identity, contact, insurance, billing, scheduling, and treatment records across gastroenterology and primary-care operations.
Specialty clinic networks collect patient identity, contact, insurance, billing, appointment, and treatment records across gastroenterology and family medicine operations.
Initially unacknowledged, the practice began issuing patient notifications in late July 2025, roughly two months after the attack, and now faces multiple class-action investigations. The Interlock group listed the practice on its dark-web leak site under the label "Family Health Specialists."
The exposure of identity and clinical data (Social Security numbers, dates of birth, medical records, and insurance information) for roughly 41,500 patients creates substantial identity-theft, medical-fraud, and insurance-abuse risk. Gastroenterology-specific diagnoses (for example colorectal findings or weight-loss procedures) add sensitivity and blackmail/embarrassment potential, and the delayed notification widened the exposure window for affected patients.
• Medical identity fraud and insurance abuse using diagnosis and insurance data | • Identity theft and synthetic identity construction using SSN and DOB | • Identity verification bypass using name + date of birth | • Blackmail or embarrassment using sensitive GI diagnoses | • Targeted phishing and vishing referencing gastroenterology care | • Doxxing and physical targeting from exposed home addresses
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware and data-extortion operation active since around September 2024, impacting businesses and critical infrastructure across North America and Europe via a double-extortion model (encrypt plus steal).
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation