On March 14, 2024, healthcare technology provider PracticeSuite appeared on the RansomHub ransomware group’s leak site, claiming that internal files had been exfiltrated during a ransomware attack. The listing indicates that anyone whose medical practice or personal health information flows through PracticeSuite’s cloud platform may now face heightened exposure, even though the exact number of affected individuals remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch practicesuite.us
Get alerted the next time practicesuite.us files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about practicesuite.us’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The RansomHub leak page states that internal files were taken from PracticeSuite.us in a ransomware incident. No specific volume of records is disclosed, and the listing does not detail which categories of data were allegedly exfiltrated beyond the generic description of internal files. The primary disclosure source is the RansomHub onion site, archived and indexed by ransomware.live at the provided URL. PracticeSuite has not yet issued a public breach notification quantifying impacted patients or practices, so the full scope of exposure is not publicly confirmed.
Why This Matters for You and Your Family
When a healthcare technology company that handles billing, scheduling, electronic health records, and patient management is breached, the ripple effects reach ordinary patients and their households. Medical information is especially sensitive because it can be used for insurance fraud, prescription scams, or targeted phishing that references your real health history. Even if you never directly signed up for PracticeSuite, your data may have passed through the platform if your doctor’s office uses it. The disclosure therefore places patients of practices using the platform at indirect but material risk.
Doxxing and Identity-Chain Implications
Healthcare breaches frequently serve as the starting point for larger doxxing chains. An attacker who obtains an email address, phone number, or policy ID from PracticeSuite’s files can cross-reference it with other leaks to build a complete profile: home address, family members’ names, employer, and even children’s online gaming handles. Once those connections are mapped, credential-stuffing attacks can hijack both adult accounts and children’s gaming profiles that reuse the same passwords or recovery emails. The result is persistent identity exposure that can last for years.