Threat Intelligence Brief
Curated summary with source attribution
Source: federmanlaw.com
Threat Risk: Medium
Victim: Terry J. Dubrow, MD, A Medical Corporation
Incident: Unauthorized access and exfiltration of patient PII and PHI from a medical network.
Impact: Exposure of Social Security numbers, driver’s licenses, and detailed medical records including X-rays.
Attacker: Unidentified threat actor
Analysis: An unauthorized actor gained access to the medical practice’s network in early 2025, remaining undetected for several months. The breach resulted in the exfiltration of a high-risk combination of PII and protected health information (PHI). This incident underscores the vulnerability of specialized medical practices to targeted network intrusions.
Recommendations: Implement robust multi-factor authentication (MFA) for all remote and internal system access.; Employ endpoint detection and response (EDR) tools to identify unauthorized network movement.; Encrypt sensitive patient data at rest to mitigate the impact of data exfiltration.
Source: Federman & Sherwood
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source