Sensitive medical data of millions of US patients has been leaked online 

Cybernews researchers have uncovered a major data breach involving the US-based dental marketing firm Gargle with a company leaking around 2.7 million patient profiles and 8.8 million appointment records online.

Key findings:

  • The leak was caused by an unsecured MongoDB database. The data owner hasn’t been officially confirmed, but clues buried in the database point toward Gargle. 
  • The leak likely stemmed from a common and often overlooked vulnerability where databases are left exposed without proper authentication due to human error. 
  • Clues point to dental marketing company Gargle as the source, raising serious questions about third-party data handling and HIPAA compliance.

What data was leaked?

  • Names
  • Dates of birth 
  • Emails
  • Addresses
  • Phone numbers
  • Gender
  • Chart IDs
  • Language preferences
  • Billing details
  • Appointment records with patient metadata, timestamps, and institutional references

What are the potential dangers of this leak?

The leaked database includes highly sensitive patient details. When combined, this information creates a full blueprint of a person’s identity — opening the door to insurance fraud, medical identity theft, and highly targeted phishing and social engineering attacks.

To read the full research report, please click here.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading