One Nephrology Associates disclosed its hack, the other stayed silent

A Kansas kidney practice reported its breach to federal regulators while a same-named Arkansas group has stayed silent months after its patient data leak.

MedRisk Staff
By
2 Min Read

A Kansas kidney practice told federal regulators about 24,088 patients caught in a months-long network intrusion, while a same-named Arkansas group whose leaked files span more than a decade of dialysis billing has still not disclosed anything, according to an investigation published September 3 by DataBreaches.

Nephrology Associates, M.D., P.A., a Kansas-based practice, filed with the HHS Office for Civil Rights on July 29 after The Gentlemen gang listed it on March 7. The practice’s notice describes unauthorized access running from January 17 to April 9 and says intruders could have reached names tied to Social Security numbers, dates of birth, driver’s license and other government identifiers, treatment and diagnosis details, and health insurance data. The gang posted no proof of its claim and never leaked files.

Nephrology Associates, PA of Arkansas handled things differently. The Insomnia group listed it on April 28, posted screenshots, and leaked a large data tranche by April 30 that security news site SuspectFile said exposed more than 30,000 patients. Five months later there is still no HHS entry and no notice on the practice’s website, DataBreaches found. A review of the leaked material turned up explanation of benefits records from 2011 through 2026, insurance files tied to dialysis patients with end-stage renal disease, remittance records, and a spreadsheet containing full Social Security numbers.

DataBreaches never heard back from the Arkansas practice’s contact form, and neither practice has been sued in a federal class action. The contrast highlights the notification gap regulators have struggled to close: the Kansas practice filed a detailed report with federal overseers, while its Arkansas namesake has stayed publicly silent since its data surfaced on the open internet.

Share This Article