On May 14, 2025, healthcare provider PDI Health appeared on the leak site of the Everest ransomware group in a listing claiming internal files were exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates that Everest listed PDI Health on its data leak portal, claiming to have stolen internal company files. The healthcare provider delivers on-site preventive care, COVID-19 testing, vaccinations, and mobile clinic services to workplaces and communities. No exact victim count has been published, and the precise volume or sensitivity of the stolen data remains unclear from available reporting. The listing appeared on the Everest leak site, which is accessible via the Tor network and tracked by ransomware monitoring services such as ransomware.live.
Internal files were allegedly exfiltrated, a common step in ransomware operations where attackers encrypt systems and threaten to publish data unless a ransom is paid. As of the publication date, there is no confirmed evidence that PDI Health has made any payment or that the files have been publicly released beyond the initial listing.
Why This Matters for You and Your Family
When a healthcare provider like PDI Health suffers a breach, the people whose records may sit in those internal files are ordinary patients, employees, and their families. Your name, address, date of birth, medical visit details, insurance information, or employer data could be among the stolen material. Once that information leaves the company’s control, it can surface on dark-web markets or be used quietly for months before you notice any misuse.