Personal information about medical professionals, including doctors and nurses, is widely available on people search sites, according to research by Incogni. The study found that 97% of doctors from major U.S. hospitals had profiles on at least one data broker site, with many appearing on multiple platforms. This widespread exposure increases the risk of harassment, unwanted contact, and potential physical harm, especially as sensitive details like home addresses and phone numbers are easily accessible. The level of exposure varies by state, age, and gender, with older doctors and those in certain states facing higher risks. The findings highlight the growing challenge for healthcare organizations to protect staff privacy and safety in an era of rampant data aggregation.
In addition to external data exposure, healthcare organizations face significant insider threats, particularly from employees snooping into patient records without authorization. Insider access can be motivated by curiosity, personal relationships, or malicious intent, such as identity theft or public embarrassment. A recent case involving the University of Miami Health System (UHealth) underscores the difficulty in preventing and detecting such incidents, as well as the reluctance of some institutions to share lessons learned. Addressing both external and internal privacy risks is critical for healthcare leaders to safeguard their workforce and maintain trust in clinical operations.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
Incogni researchers reported that in a sample of 786 doctors at major U.S. hospitals, 97% appeared on at least one people-search site and 72% were likely exposed across multiple sites. The report warned that data-broker exposure increases risks such as harassment, stalking, intimidation, and targeted fraud against healthcare staff.
A University of Miami Health System presentation discussed employee snooping in electronic health records and indicated a significant incident had occurred, though only limited details were publicly provided. The presentation also described UHealth's approach as focused on deterrence and proportional discipline rather than automatic termination for every violation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.