Petaluma Health Center
bd_0ffdbcef2ecd77f1 · schema v1 · pii pii-v1
Full breach record for Petaluma Health Center →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Karakurt on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
The Petaluma Health Center is a Federally Qualified Health Center that strives to care for the "whole" individual by providing excellent care for all patients, regardless of one's ability to pay for services. We do not know whether their patients personal and medical information was stored unsafely because of their disability to pay but we have almost 490GB of this Health Center on our servers. Along with that we've obtained a good amount of financial information (numerous declarations, payment docs, tax forms ...) and personal employees information (SSNs, passports, phone numbers, addresses etc).That is going to be interesting.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Apr 12, 2023
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Indiana State AGbd_6c999b9ec6ec853f2023-04-24 · +11dCandidate
- Maine State AGbd_b5c781e6b089596b2023-04-28 · +15dVerified
- California State AGbd_bdc46d25c14edb8f2023-04-28 · +15dVerified
- Montana State AGbd_c33ded56f74f4a622023-04-28 · +15dVerified
Show 5 more filings ↓Show fewer ↑up to 53d gap
- Montana State AGbd_6c47d4d37e101db42023-06-01 · +49dVerified
- California State AGbd_7327f7af51c2e39f2023-06-02 · +50dVerified
- HHS OCRbd_79efc5514452341c2023-06-02 · +50dVerified by operator
- Oregon State AGbd_a1ea4f5d3b6c44e82023-06-02 · +50dVerified
- Massachusetts State AGbd_8ab10097ba8d295e2023-06-05 · +53dVerified
Filing propagation · 10 filings · 6 states
View merged incident ↗Pattern: first filing Apr 12, last Jun 5 (MA) — a 53-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
karakurt
According to ransomware.live, Karakurt is a pure data-extortion group (no encryption) assessed with high confidence to be the extortion arm of the Conti ransomware group, active from 2021, that steals data and threatens to auction or publish it unless ransoms ranging from $25,000 to $13 million are paid.