On May 18, 2024, the Center for Digestive Health in Orlando appeared on the leak site operated by the Bianlian ransomware group. Patients and their families whose medical and personal records are held by the practice now face the possibility that internal files containing sensitive health and identity information have been stolen and may be published or sold.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details from the Leak-Site Listing
The Bianlian leak site lists cdhorlando.com and states that internal files were exfiltrated during a ransomware attack. The listing does not disclose the exact number of records affected, the specific types of documents taken, or any ransom demand. It simply states that data was stolen and gives the medical practice a short window to negotiate before samples or the full archive are released. Public reporting on Bianlian indicates the group follows this pattern of posting victim companies with minimal initial detail, then gradually increasing pressure by leaking proof files.
Why This Matters for You and Your Family
If you or a member of your family has ever been treated at the Center for Digestive Health, your protected health information is likely among the stolen material. This can include names, dates of birth, Social Security numbers, insurance details, diagnoses, treatment records, and billing information. Exposure of such data creates immediate financial and medical-privacy risks. Criminals can use it to file fraudulent tax returns, open accounts in your name, or impersonate you to obtain prescription medications. For anyone managing chronic digestive conditions, the leak also raises the prospect of sensitive clinical notes being publicly traded or mocked on underground forums.
Doxxing and Identity-Chain Risks
Health records rarely exist in isolation. A single leaked file often links your medical patient ID to home address, phone number, email, and sometimes employer or family-member details. Attackers chain this information with credentials from other breaches to take over email accounts, reset passwords on banking or government portals, and build a complete identity profile. Children’s records are sometimes included when a parent brings them to the same practice, creating long-term exposure that can follow them into adulthood. Gaming accounts tied to family email addresses become easy targets once those addresses surface in a medical breach, turning one health incident into a cascade of account takeovers and doxxing.