INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Medical Practice Exposes Patient Details via Data Breach Incident
| 2025-07-26 03:27 DATA BREACH
Executive Summary
AI-generated
A medical practice in Huntington, New York exposed the personal details of 40,000 patients after a digital data repository containing records from Cohen Bergman Klepper Romano Mds PC was left publicly accessible. The incident occurred on January 25th, 2018, when an exposed port within IT systems was discovered by UpGuard Director of Cyber Risk Research Chris Vickery. This exposed port allowed anyone to access the information knowing only the server's IP address, revealing sensitive data including patient names, Social Security numbers, dates of birth, phone numbers, insurance information, and more. The attack works by exploiting a misconfigured rsync utility that was not properly secured against public access. As soon as UpGuard notified Accenture about this publicly exposed information, immediate action was taken to secure the open buckets and prevent further access.
Technical Mitigations AI-generated
• Configure rsync server's "hosts allow/deny" functions to restrict access to only specific IP addresses.
• Regularly review and patch vulnerable ports, such as port 873, that are not properly secured against public access.
• Implement a robust backup system for sensitive data, using techniques like encryption and secure storage solutions.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
da•••••.net
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Intelligence Sources
Upguard
2025-07-26