Petaluma Health Center
bd_0ffdbcef2ecd77f1 · schema v1 · pii pii-v1
Full breach record for Petaluma Health Center →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Karakurt on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
The Petaluma Health Center is a Federally Qualified Health Center that strives to care for the "whole" individual by providing excellent care for all patients, regardless of one's ability to pay for services. We do not know whether their patients personal and medical information was stored unsafely because of their disability to pay but we have almost 490GB of this Health Center on our servers. Along with that we've obtained a good amount of financial information (numerous declarations, payment docs, tax forms ...) and personal employees information (SSNs, passports, phone numbers, addresses etc).That is going to be interesting.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_b5c781e6b089596bMaine State AGfiled 2023-04-28(15d gap)Verified
- bd_c33ded56f74f4a62Montana State AGfiled 2023-04-28(15d gap)Verified
- bd_6c47d4d37e101db4Montana State AGfiled 2023-06-01(49d gap)Verified
- bd_a1ea4f5d3b6c44e8Oregon State AGfiled 2023-06-02(50d gap)Verified by operator
Source provenance
- Source URL
- https://www.ransomware.live/
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 12, 2023
- Raw hash
- ed746a56934143bcbc8ad167f9ff8b7e685680756ae1a107a8e6713ae98094db
Reporting entity
- Name
- karakurt
Victim entity
- Name
- Petaluma Health Centernorm: petaluma health center
- Domain
- phealthcenter.org
- Industry
- Healthcarellm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· karakurt
- Threat actor
- KarakurtExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.