Heart South Cardiovascular Group
ent_1caf02caca4fef35fc4c37ac
Disclosures
4
State AG · Leak Site · HHS OCR · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
20,577
as filed · HHS OCR AL
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Heart South Cardiovascular Group
- Normalized
- heart south cardiovascular— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- heartsouthpc.com
Disclosure history (4)newest first
- ⛰️New Hampshire State AGas victim2026-04-13
Heart South Cardiovascular Group notified the New Hampshire Attorney General of a cybersecurity incident affecting approximately 2 NH residents. On November 11, 2025, the group learned an unauthorized party claimed to possess data. Investigation found no unauthorized network access, but a bad actor posted limited data on the dark web. Patient PII (names, SSNs, DOB) and PHI (treatments, diagnoses) were potentially exposed. Notifications began April 6, 2026, offering credit monitoring via Kroll.
- 🦞Maine State AGas victim2026-04-06
Heart South Cardiovascular Group PC (Alabaster, AL) notified 3 Maine residents (46,666 total) of a cybersecurity incident. Around Nov 11, 2025, an unauthorized party claimed to possess and later posted limited Heart South data on the dark web. No confirmed network intrusion or data theft found. PHI potentially affected. Discovered Feb 12, 2026. Kroll identity monitoring offered 12 months.
- GLOBALLeak Siteas victim2025-11-10
Heart South Cardiovascular Group Heart South is a leading provider of comprehensive cardiac and vascular care in Central Alabama. More
- ALHHS OCRas victim2024-06-13
Heart South Cardiovascular Group (AL), a cardiovascular healthcare provider, reported to HHS OCR on 2024-06-13 a ransomware attack affecting 20,577 individuals. Compromised PHI on a network server included names, addresses, dates of birth, driver's license numbers, SSNs, diagnoses, lab results, medications, health insurance information, claims/financial data, and other treatment information. The CE notified HHS, individuals, and the media, implemented new technical safeguards, and retrained workforce members. OCR provided technical assistance on the HIPAA Breach Notification Rule.