← Cardiology Associates of Port Huron

2026 Cardiology Associates of Port Huron — Orova extortion listing (unverified); actor claims >200k patient records incl. SSNs

2026 200.0K records affected Share on X

Data compromised

Actor-claimed and partially corroborated by leak-site proof screenshots reviewed by DataBreaches.net: patient names, postal and email addresses, home and cell phone numbers, dates of birth, clinical procedure/test types with dates of service, health insurance details, and full Social Security numbers in one query-result screenshot. Listing claims 244,215 files totalling 144 GB. Not company-confirmed — unverified.

Technical writeup

Unverified extortion / leak-site claim — Orova, a self-described startup ransomware-as-a-service operation that told DataBreaches.net it is a branch of "another group that disappeared earlier," listed Cardiology Associates of Port Huron on its dark-web leak site on July 10, 2026. DataBreaches.net reported on the listing on August 6, 2026 and described eight proof screenshots containing patient names, postal and email addresses, home and cell phone numbers, dates of birth, procedure and test types with service dates, health insurance information, and — in one query-result excerpt — full Social Security numbers alongside patient names. The listing claims 244,215 files comprising 144 GB, and an Orova spokesperson claimed "the full data of Cardiology Associates, like SSN, number, address, transaction history, name, email, patient record, x-ray image, etc., >200k records." DataBreaches.net said the screenshots tend to support much of that claim and that it validated some patient data independently. According to the actor, the practice was compromised on June 25, 2026, contacted Orova from a proton.me address, received sample files and a proof-of-decryption, then stopped responding — after which the group published a partial listing with a countdown clock. Orova also said it encrypted some servers but that the practice had cloud backups. Cardiology Associates of Port Huron, which is affiliated with McLaren, had issued no public statement and no HHS OCR breach report was visible at indexing time. recordsAffected 200,000 is the actor claim, labelled unverified — treat it as a claim, not an attested notification count, until the practice or a regulator publishes a figure.

Root cause

Unverified Orova ransomware-as-a-service extortion listing naming Cardiology Associates of Port Huron (Michigan). The actor told DataBreaches.net the practice was compromised on June 25, 2026 and that some servers were encrypted; the practice had not confirmed any incident at indexing time.

References