DEFENCE / RADAR

Public snapshot

Brookhaven ENT Allergy and Facial Surgery·Healthcare·

Personal and health information was exposed.

Structured public source; classification preserves the source's evidence status. The exact technical root cause is not established in the attached record.

Report freshness and timeline

Incident occurred
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Regulator confirmed
Mechanism
Entry path: CareCloud, Inc.
Consequence
Reported: Personal and health information was exposed.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Brookhaven ENT Allergy and Facial Surgery
Industry
Healthcare
Disclosed
Event date
Third party
CareCloud, Inc.
Affected asset
electronic medical record system and network server
Product / vendor
electronic health record service
Country
US
Data involved
Health Data · Personal data
Reported impact
Data exposure
Attached evidence
4 independent domains · 4 sources

2)Evidence-backed incident path

  1. 01

    Third party

    CareCloud, Inc.

    ConfidencePrimary
    Exact excerpt

    third-party electronic health record service provider, CareCloud, Inc.

    brookhavenent.com · May 28
    E1
  2. 02

    Affected product

    electronic health record service

    ConfidencePrimary
    Exact excerpt

    third-party electronic health record service provider

    brookhavenent.com · May 28
    E2
  3. 03

    Reached

    electronic medical record system and network server

    ConfidenceSecondary
    Exact excerpt

    electronic medical record system and network server

    classactionu.org · Aug 17
    E3
  4. 04

    Observed

    Personal and health information was exposed.

    ConfidenceProbable
    Exact excerpt

    personal and health information exposed

    classactionu.org · Aug 17
    E4

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The exact technical root cause
  • Whether a regulatory fine followed
  • That a Defence review would have prevented this incident

4)Relevance to your product

Third-party access can inherit more reach than the product team intended.

This pattern applies when…

  • Products that rely on third-party electronic health record providers.

Diagnostic questions

  1. Can an integration reach production secrets or customer data?
  2. Are scopes narrower than the vendor's full workspace access?
  3. Can tokens be isolated and revoked without breaking the product?

This incident does not establish your product's risk.

5)Sector context — Healthcare

293 incident threads in the 365-day public record
  1. 1 incident threads
  2. 1 incident threads
  3. 0 incident threads
  4. 1 incident threads
  5. 24 incident threads
  6. 18 incident threads
  7. 32 incident threads
  8. 26 incident threads
  9. 27 incident threads
  10. 74 incident threads
  11. 61 incident threads
  12. 28 incident threads
Same incident family
97
Cause not publicly established
Confirmed share
60%
177 confirmed · 116 reported
Display family
Other
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Healthcare in Radar →

6)Defence control mapping

What Defence can test

Third-party integration review

  • Can an integration reach production secrets or customer data?
  • Are scopes narrower than the vendor's full workspace access?
  • Can tokens be isolated and revoked without breaking the product?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

4 attached sources across 4 independent domains. At least one primary source is attached.

  1. E3, E4
    classactionu.orgBrookhaven ENT Allergy and Facial Surgery Data Breach Lawsuit - Class Action UOther public report · Aug 17 · Cited
    Other public reportCited
    Exact excerpt
    personal and health information
  2. E1, E2
    brookhavenent.comSavannah Stockton, MD - Brookhaven ENT, Allergy, Aesthetics, HearingOrganization statement · May 28 · Primary
    Organization statementPrimary
    Exact excerpt
    Special Announcement Concerning Patient Privacy
  3. S3
    HHS OCR Breach PortalBrookhaven ENT Allergy and Facial Surgery — HHS breach reportRegulator record · Jul 24 · Primary
    Regulator recordPrimary
  4. S4
    claimdepot.comBrookhaven ENT Data Breach Affects 30,403 PatientsOther public report · Aug 17 · Attached
    Other public reportAttached
    Exact excerpt
    protected health information

Does this integration boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →