DisclosureLens
GLOBALUnknownRansomwareEverestLow

Pacific Pulmonary Medical Group

bd_a2695396a6b93d18 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Oct 4, 2024

To disclose

Affected

Not disclosed

Linked

5 filings

Confidence

60%
Full breach record for Pacific Pulmonary Medical Group

Press / market disclosure — not a breach-notification filing

A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.

Pacific Pulmonary Medical Group patient information dumped by Everest Ransomware Team - DataBreaches.Net. Pacific Pulmonary Medical Group (PPMG): The Pacific Pulmonary Medical Group (PPMG) in California was the victim of a cyberattack by the Everest Ransomware Team, which stole protected health information and patient personal data, including Social Security numbers and health insurance details. The data was published on the dark web and includes images of insurance cards and driver's licenses, as well as CSV files containing health and personal contact information. To date, PPMG has not published a data breach notification on its website and has not responded to information requests. Linked ransomware group: everest.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Oct 4, 2024

Press report

Corroborated · see linked filings

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Attack → press

Compliance clock

Not assessable

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 2 states

View merged incident ↗
PressOct 4 · first · this page

Pattern: first filing Oct 4, last Jan 3 (CA) — a 91-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market reportThis record

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • incident type + narrative only (may be machine-translated)
  • discovery date
  • materiality
  • affected count
  • data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2021-09-09

everest

According to ransomware.live, Everest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit card information, and more. The Everest ransom group leaks the victim's data to the darknet and they announced that any victim that will not contact them will suffer from a data leak and they will not delete hist files for future usage.

399 tracked hereFull profile →