Central Florida Hand Specialists, a medical practice based in Orlando, Florida, experienced a cyberattack. On July 8, 2025, the RHYSIDA ransomware group posted on the dark web that they had compromised the medical practice's internal network.
According to the dark web listing, RHYSIDA claimed to have exfiltrated sensitive data from the organization and threatened to publish it. The cybercriminals also provided sample screenshots as proof of access on their dark web portal, indicating the breach’s authenticity.
It is believed that the ransomware attack compromised sensitive patient data, including both personally identifiable information (PII) and protected health information (PHI). Exposed information may include names, dates of birth, contact details, driver's license or state ID copies, Social Security numbers, medical records, insurance information and possibly payment information.
This type of data breach is considered severe because it puts sensitive data at risk of public exposure or sale on criminal forums. RHYSIDA is known for targeting healthcare providers and threatening to leak stolen data if their ransom demands are not met.
Central Florida Hand Specialists has not yet issued a public statement detailing their response to the data breach. The medical practice will be required to make certain state and federal disclosures and should notify impacted individuals by mail.
If you believe your personal and protected health information may have been compromised in this breach:
For more information about the medical practice, visit the Central Florida Hand Specialists website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.