
Doctor Alliance Breach
Nov 18, 2025
386,583 rows
What happened in the Doctor Alliance Breach?
DataBreach.com Team · December 14th 2025, 7:00 pm EST
1. Who is Doctor Alliance?
To understand the breach, you first need to know who the victim is. Doctor Alliance is a Dallas-based technology company that works behind the scenes in healthcare. They don’t treat patients directly; instead, they provide document management and billing services for home health agencies and doctors.
Think of them as the "digital filing cabinet" for healthcare providers. When a doctor visits a patient at home, the forms they sign, the billing codes they enter, and the treatment plans they create often pass through Doctor Alliance’s system.
2. What Happened? (The Incident)
In early November 2025, a cybercriminal going by the alias "Kazu" posted a message on a dark web forum claiming to have hacked Doctor Alliance.
- The Claim: Kazu said they had stolen 353 GB of data, which they counted as 1.24 million files.
- The Ransom: They demanded $200,000 to delete the data, threatening to sell it to other criminals if the company didn't pay by November 21.
- The Proof: To prove they weren't lying, the hacker leaked a sample of the data (about 200 MB), which included scanned images of actual patient records-things like intake forms, medication lists, and Medicare numbers.
3. The Panic & Media Frenzy
When the news broke, the headline number was "1.2 Million."
Because the hacker said they stole "1.24 million files," many people and news outlets feared this meant 1.2 million patients had their identities stolen. This triggered an immediate backlash:
- Lawsuits: Lawyers almost immediately filed class-action lawsuits against Doctor Alliance and some of its clients (like Prima Care), accusing them of negligence before the full scope was even known.
- Company Response: Doctor Alliance admitted that an unauthorized user had accessed a single client account due to a software vulnerability (which they quickly patched), but they were skeptical about the massive numbers the hacker was claiming.
4. The Reality Check (Our Analysis)
This is where the distinction between "files" and "people" becomes critical. A single patient might have 50 different "files" associated with them-scanned ID cards, weekly signed forms, billing records, etc.
We analyzed the actual data dump to see how many unique people were truly exposed. The results were significant, but much smaller than the "1.2 million" headline suggested:
- 386,600 Unique Phone Numbers: This was the most common data point found.
- 33,100 Unique SSNs: This is the most dangerous exposure, but it affects ~33k people, not millions.
- 7,900 Unique Emails: A relatively small number of email addresses were involved.
The Bottom Line: The breach was serious - especially for the 33,000 people whose Social Security numbers were leaked-but it was not the "million-person" catastrophe that the initial file count suggested.










