On January 26, 2025, the Qilin ransomware group added Central Texas Pediatric Orthopedics to its leak site, claiming that internal files had been exfiltrated from the Austin-area medical practice.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch ctpomd
Get alerted the next time ctpomd files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about ctpomd’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the group posted details of the incident on its dark-web leak portal. The practice, founded in 1990 by Dr. Jay Shapiro, operates multiple locations serving pediatric patients in the Austin and Cedar Park area. Available reporting describes the data as internal files taken during a ransomware attack, though the exact volume and specific types of records have not been publicly detailed. No confirmed victim count has been released. The listing appeared on the Qilin leak site, which is tracked by ransomware intelligence platforms such as ransomware.live.
Why This Matters for You and Your Family
When a local medical provider is hit, the information at risk often includes names, dates of birth, addresses, phone numbers, insurance details, and clinical notes for children and parents alike. Pediatric records are especially sensitive because they tie a child’s identity to family contact information that can be used for years. Even if your family is not a patient at this specific practice, the same attack techniques are used against thousands of healthcare providers, schools, and small businesses that hold your data. A single breach can give criminals the starting point they need to target you personally.
The Doxxing and Identity-Chain Implications
Medical breaches rarely stop at one dataset. Attackers combine leaked healthcare information with credentials from other sources to build detailed profiles. A parent’s email and password stolen from a clinic portal can unlock the same credentials on retail sites, banking apps, or children’s gaming accounts. Once one account falls, the chain grows: recovered passwords lead to linked phone numbers, home addresses, and social-media handles. This is exactly how doxxing campaigns escalate from data exposure to harassment and identity theft. Credential leaks like this one cascade into account takeovers that can affect every member of a household.