Physicians’ Primary Care Data Breach: 1.8TB Stolen

Published
August 5, 2025
Updated
August 5, 2025
Physicians’ Primary Care Data Breach: 1.8TB Stolen
Physicians' Primary Care of Southwest Florida
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Physicians' Primary Care of Southwest Florida

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

Physicians’ Primary Care of Southwest Florida, a medical practice based in Southwest Florida, experienced a data breach. The cybersecurity incident was first detected on Sept. 17, 2024, and unauthorized access is believed to have started on Sept. 15, 2024.

The breach was the result of a ransomware attack carried out by the BianLian group, who claimed responsibility on the dark web and stated they exfiltrated approximately 1.8 terabytes of sensitive data. The compromised data includes both personally identifiable information (PII) and protected health information (PHI) of patients and employees.

Exposed data may include names, Social Security numbers and health information related to care and treatment received at Physicians’ Primary Care of Southwest Florida. According to the ransomware group's dark web post, the stolen data set also contained operational data, contracts and NDAs, passports and IDs, employee records, business files, accounting data, email archives, SQL databases, file server data and network user folders.

The data breach was disclosed to the U.S. Department of Health and Human Services on Nov. 14, 2024. The company also posted a detailed notice of security incident on its website, which was updated on July 18, 2025.

Physicians’ Primary Care of Southwest Florida's response

Upon discovering the unauthorized access and ransomware attack, Physicians’ Primary Care of Southwest Florida initiated its incident response protocols. In addition to required state and federal disclosures, the organization has notified affected individuals by mail and offering free credit monitoring and identity theft protection services.

If you receive a notice from Physicians’ Primary Care of Southwest Florida about this breach, you may want to:

  • Enroll in the free credit monitoring and identity theft protection services offered.
  • Monitor your credit reports and financial accounts for any unusual activity.
  • Be alert for phishing emails or phone calls that may use your exposed information.
  • Consider placing a fraud alert or credit freeze with major credit bureaus.

More information about the medical practice group can be found on the Physicians’ Primary Care of Southwest Florida website.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
September 16, 2017
Breach Discovered Date
September 17, 2024
Total People Affected
Information Types Exposed
  • names
  • health information related to care and treatment received at PPC
  • potentially social security numbers
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image