Heart South Cardiovascular Group
ent_1caf02caca4fef35fc4c37ac
Disclosures
8
State AG · HHS OCR · Leak Site · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
46,666
nationwide · HHS OCR AL
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Heart South Cardiovascular Group
- Normalized
- heart south cardiovascular— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- heartsouthpc.com
Disclosure history (8)newest first
- New Hampshire State AGas victim2026-04-13
Heart South Cardiovascular Group notified the New Hampshire Attorney General of a cybersecurity incident affecting approximately 2 NH residents. On November 11, 2025, the group learned an unauthorized party claimed to possess data. Investigation found no unauthorized network access, but a bad actor posted limited data on the dark web. Patient PII (names, SSNs, DOB) and PHI (treatments, diagnoses) were potentially exposed. Notifications began April 6, 2026, offering credit monitoring via Kroll.
- ALABAMAHHS OCRas victim2026-04-06
Heart South Cardiovascular Group reported to HHS on 2026-04-06 a Hacking/IT Incident affecting 46666 individuals. Breached information located on Network Server.
- Nebraska State AGas victim2026-04-06
Heart South Cardiovascular Group, PC notified Nebraska residents of a cybersecurity incident discovered on November 11, 2025, where an unauthorized party claimed to possess patient data. Forensic investigation found no network access or data theft, but a bad actor posted limited data on the dark web. Kroll was engaged to provide complimentary identity monitoring services to affected patients.
- Maine State AGas victim2026-04-06
Heart South Cardiovascular Group, PC reported an unauthorized access incident on November 11, 2025, where a bad actor claimed to possess data and posted limited data on the dark web. The investigation found no evidence of network access or data theft, but confirmed patient PHI was stored on affected systems. 46,666 individuals were notified, including 3 Maine residents. Identity monitoring services were offered.
- GLOBALLeak Siteas victim2025-11-10
Heart South Cardiovascular Group Heart South is a leading provider of comprehensive cardiac and vascular care in Central Alabama. More
- Massachusetts State AGas victim2024-09-25
Heart South Cardiovascular Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-09-25. 1 Massachusetts residents were affected.
- Illinois State AGas victim2024-09-01
HEART SOUTH CARDIOVASCULAR GROUP filed a data-breach notice with the Illinois Attorney General in September 2024 (case 24-09-074). The register records the breach as discovered on May 29, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- ALABAMAHHS OCRas victim2024-06-13
Heart South Cardiovascular Group (AL), a cardiovascular healthcare provider, reported to HHS OCR on 2024-06-13 a ransomware attack affecting 20,577 individuals. Compromised PHI on a network server included names, addresses, dates of birth, driver's license numbers, SSNs, diagnoses, lab results, medications, health insurance information, claims/financial data, and other treatment information. The CE notified HHS, individuals, and the media, implemented new technical safeguards, and retrained workforce members. OCR provided technical assistance on the HIPAA Breach Notification Rule.