Pacific Pulmonary Medical Group
bd_a2695396a6b93d18 · schema v1 · pii pii-v1
Full breach record for Pacific Pulmonary Medical Group →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Pacific Pulmonary Medical Group patient information dumped by Everest Ransomware Team - DataBreaches.Net. Pacific Pulmonary Medical Group (PPMG): The Pacific Pulmonary Medical Group (PPMG) in California was the victim of a cyberattack by the Everest Ransomware Team, which stole protected health information and patient personal data, including Social Security numbers and health insurance details. The data was published on the dark web and includes images of insurance cards and driver's licenses, as well as CSV files containing health and personal contact information. To date, PPMG has not published a data breach notification on its website and has not responded to information requests. Linked ransomware group: everest.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Oct 4, 2024
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteeverestbd_c6f25a8a3412a7f52024-10-25 · +21dVerified by operator
Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_d6f19c175e0f5bf92024-12-31 · +88dVerified
- Massachusetts State AGbd_571d897cb477c29c2025-01-03 · +91dVerified by operator
- California State AGbd_a14da3c468ce7bdd2025-01-03 · +91dVerified
Filing propagation · 4 filings · 2 states
View merged incident ↗Pattern: first filing Oct 4, last Jan 3 (CA) — a 91-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
everest
According to ransomware.live, Everest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit card information, and more. The Everest ransom group leaks the victim's data to the darknet and they announced that any victim that will not contact them will suffer from a data leak and they will not delete hist files for future usage.