INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lena AI Health Breach Exposes Houston Methodist Patients' Medical Info
| 2026-01-28 18:46 AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH
Executive Summary
AI-generated
On June 1, 2025, Serviceaide, a provider of AI-powered healthcare software, suffered a data breach that exposed the protected health information of at least six federal class-action lawsuits' patients. The breach was caused by an unsecured database and involved 483,000 patients from Catholic Health in Buffalo, New York. A recent hacking forum listing reveals another breach involving "digital helper" Lena Health, which stored 2,134 patients' complete PHI in an unencrypted database export sitting in a public-facing S3 bucket. The attack was carried out via a major vulnerability that went public in early December, and the attackers were contacted by FulcrumSec on January 10 but had not responded as of January 15.
Technical Mitigations AI-generated
• Patch the major vulnerability in early December, specifically addressing the unsecured database export sitting in a public-facing S3 bucket.
• Block or hunt for API keys and staff login credentials to prevent unauthorized access to sensitive data.
• Use a technique such as file integrity monitoring (FIM) to detect anomalies in PHI storage on vulnerable servers accessible by the entire internet.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
da•••••.net
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
Tactical Metrics
Intelligence Sources
Data Breaches
2026-01-28