A cybersecurity researcher discovered that a database containing nearly 150,000 patient records belonging to Archer Health, a California-based provider of home health and palliative care services, was left exposed on the internet without password protection. The unencrypted database, totaling 23.7 gigabytes, included highly sensitive medical documents such as names, patient ID numbers, Social Security numbers, physical addresses, and phone numbers. The exposed records also featured assessments, home health certifications, plan of care documents, and discharge forms, all containing personally identifiable information (PII) and protected health information (PHI). Diagnoses, treatments, and other sensitive health-related data were among the information accessible to anyone who found the database online. The security researcher, Jeremiah Fowler, reported that it was unclear whether Archer Health or a third-party contractor was responsible for managing the database. The duration of the exposure remains unknown, as does whether any unauthorized parties accessed or exfiltrated the data before the discovery. The 'date modified' metadata on the files did not provide clear evidence of when the exposure began. The incident highlights significant risks to patient privacy and the potential for identity theft or fraud due to the nature of the data involved. Archer Health was notified of the exposure, but details regarding their response or mitigation efforts have not been disclosed. The lack of basic security controls, such as password protection and encryption, represents a serious lapse in data protection practices, especially for sensitive healthcare information. Regulatory implications may arise, given the potential violation of HIPAA and other data privacy laws. The exposure underscores the importance of robust third-party risk management, as it is not yet confirmed whether a vendor was involved. Healthcare organizations are reminded of the critical need to secure all databases containing PHI, regardless of whether they are managed internally or by external partners. The incident serves as a cautionary example for the healthcare sector, which remains a frequent target for data breaches and accidental exposures. Ongoing investigations may reveal further details about the scope of the exposure and any potential impact on affected patients. Organizations are urged to review their data storage and access policies to prevent similar incidents.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Security news outlets reported the Archer Health data exposure, bringing public attention to the leak of approximately 150,000 records. Coverage described the incident as involving sensitive medical and home health care data.
A publicly accessible database belonging to Archer Health exposed roughly 150,000 records on the web, including sensitive home health care and medical information. Reporting indicates the leak involved about 23 GB of data and affected patient-related records.
3 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.