282,000 Patients' Medical Records Stolen in Premier Medical Group Breach
A New York cardiology and neurology group is notifying patients after criminals accessed files containing names, diagnoses, and insurance details in a June attack.

Key points
- Premier Medical Group (PMG), a Hudson Valley, New York healthcare provider, confirmed criminals stole personal and medical data belonging to 282,075 patients.
- Attackers accessed files on June 14, according to PMG's own investigation.
- Stolen data includes names, dates of birth, diagnosis records, medication details, and health insurance information.
- PMG has not identified who carried out the attack or how they got in.
- PMG notified the US Department of Health and Human Services (HHS), the federal body that oversees patient privacy rules, this week.
Premier Medical Group, a multi-specialty clinic group serving patients across cardiology, neurology, dermatology, and internal medicine in New York's Hudson Valley, is sending breach notifications to 282,075 patients after criminals broke into its systems and copied many sensitive records.
PMG's incident notice says the attackers accessed certain files on June 14. Some of PMG's systems were disrupted at the time. The group has not explained what kind of attack it was or how the criminals first got in. This is the fifth medical-records breach Threat Vectr has covered in the last 90 days, a run that included the 9.5 million-record Aesto Health theft we reported on 1 September.
What information was taken?
Quite a lot. The stolen files contained names, contact details, dates of birth, treatment and diagnostic information, medication records, health insurance details, dates of service, provider names, and internal patient ID numbers.
That combination is useful to fraudsters. A criminal holding your insurer's name, your date of birth, and your diagnosis can file fake medical claims in your name, a form of identity theft called medical fraud. It can damage your insurance history and create false entries inside your medical file.
| Data type | Included in breach |
|---|---|
| Name and contact details | Yes |
| Date of birth | Yes |
| Treatment and diagnosis records | Yes |
| Medication information | Yes |
| Health insurance details | Yes |
| Internal patient ID number | Yes |
Should patients be worried?
Yes, concretely. PMG's own advice is worth following: check every explanation-of-benefits statement (the summary your insurer sends after any medical visit) and look for services you never received. If anything looks off, call your insurer directly.
Social Security numbers were not listed among the stolen data types, so the immediate risk skews toward medical fraud rather than full identity theft. That picture could change if PMG's investigation turns up more. No ransomware or extortion group has publicly claimed the attack, which SecurityWeek noted in its original reporting. A quiet crew sitting on the data, or a ransom paid before any public claim appeared, are both plausible readings. PMG has said nothing publicly on that point.
What should affected patients do?
Check your mail. PMG is sending written notifications to affected individuals. Once you receive one, request a free copy of your credit report and scan it for unfamiliar medical accounts or collection notices. You can also contact your insurer and ask them to flag your account for unusual claims activity.
Patients who spot unrecognised services on any statement should call their provider or health plan straight away. That's the right call.



