Who Is Actually Counting the Records?
# Who Is Actually Counting the Records?
The current wire would have you believe we are witnessing an unprecedented coordinated assault on the healthcare sector. The numbers are designed to trigger panic: 3.75 million patient records exposed in one breach, another 3.75 million via CareCloud, and a further 2.8 million from Baylor Genetics. When you aggregate these figures into a single headline, it looks like a systemic failure of medical infrastructure—a crisis of "healthcare security" that demands urgent investment in next-generation defence tools and perhaps a few more emergency government grants for hospital IT departments. The consensus is simple: the attackers have evolved, and our defences are lagging behind.
It’s a tidy narrative. It justifies budget increases and makes for excellent press releases from cybersecurity firms selling "AI-driven resilience."
The problem with this narrative is that it treats the theft of millions of records as an inevitable consequence of sophisticated attacks rather than a voluntary choice in data architecture. If we look at the paperwork, the story isn't about the attackers; it’s about the hoarding. There is no technical reason why a single vulnerability should grant access to 3.75 million patient files simultaneously. That only happens when an organisation decides that convenience outweighs the basic principle of segmentation.
We see this across the board, not just in clinics. CarGurus has just seen north of 12 million accounts exposed. The scale is consistent because the habit is consistent: keep everything in one giant, accessible bucket and hope the fence holds. When it doesn't, the industry calls it a "catastrophic breach." I call it a failure to follow data minimisation rules that have been sitting on the books in Brussels for years.
Under GDPR, specifically Article 5(1)(c), data should be "adequate, relevant and limited to what is necessary." Most of these millions of records shouldn't have been online or accessible via a single credential set in the first place. But auditing your database to see what you actually need to keep is tedious work. It requires a level of administrative discipline that doesn't fit into a quarterly growth report. It is far easier for a CISO to point at a "sophisticated threat" than to admit they’ve been ignoring their own data retention policy since 2019.
The regulatory machinery is, as usual, slow and largely toothless. While we wait for fines to be levied—which usually happens years after the victims have already had their identities sold three times over on a forum—the companies continue to operate under the assumption that it's cheaper to pay a penalty once every few years than to actually re-engineer their storage.
I recall similar patterns during the early days of the cloud migration in Oslo, where "scalability" became a euphemism for "we’ve stopped worrying about where the data actually lives." The parallel here is that we've moved from hoarding on-premise to hoarding in the cloud, but the lack of segmentation remains.
There is a second-order effect here that rarely makes the headlines. When these massive breaches hit, the strain doesn't just fall on the victim company; it spills over onto public infrastructure. Look at Poland, where citizens are currently rushing to government services to check if their data was exposed following the MyDr breach. The attackers didn't just steal records; they effectively launched a distributed denial-of-service attack on the Polish state’s administrative portals by triggering a mass panic of legitimate users.
Who benefits from the "sophisticated assault" hype? Primarily the vendors who sell the "silver bullet" software that promises to stop the next breach without requiring the company to actually delete any old data. They get to sell a cure for a symptom while ignoring the disease.
The attackers benefit too, though in a different way. Groups like Rhysida—who are currently demanding 30 BTC after allegedly lifting 5.79 TB of data from a Berlin entity—rely on this atmosphere of panic. The higher the perceived "sophistication" of the attack, the more likely a board of directors is to authorise a ransom payment out of sheer terror, rather than conducting a cold analysis of what was actually stolen.
If we stop focusing on the attackers for a moment and look at the disclosure logs, we find the real story. The gaps between the date of intrusion and the date of notification are often vast. By the time the 2.8 million people at Baylor Genetics get their letters in the post, the data is already stale and well-distributed.
The question isn't why the attackers are so good at getting in. The question is why we are still storing millions of records in a way that makes them so easy to take. Until the fines for over-retention exceed the cost of proper database architecture, we can expect these million-record milestones to keep appearing on my desk every Tuesday.
I suspect the next big "crisis" will look exactly like this one: a massive number followed by a claim of sophistication, while the actual cause remains a failure to delete a spreadsheet from 2014.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- Baylor Genetics data breach hits 2.8M - Medical Buyer Google News Security
- Healthcare data breach exposes 3.75M patient records - Fox News Google News Security
- CareCloud Data Breach Affects 3.75 Million Americans - JFeed Google News Security
- CarGurus Data Breach Exposes 12.5 Million Accounts; Here's What Hackers Got - International Business Times, Singapore Edition Google News Security
- Anthropic warns infostealer malware is hijacking Claude sessions to drain usage BleepingComputer
- MyDr data breach: Poles rush to government service to check whether their data were exposed - CEO Magazyn Google News Security
- Over 335M records breached as cyber attacks rise in the Philippines in H1 2026 - Technobaboy Google News Security
- Chrome Web Store extensions caught stealing crypto, browser data BleepingComputer