ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C Data Breach Exposes Patient Medical and Personal Records

Published: 1 October 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: 29th September 2026

A threat actor group called Booba Project claims to have stolen 70 GB of data from Associated Gastroenterologists of Central New York, P.C., a medical practice, potentially exposing patient names, Social Security numbers, and medical records. The practice has not publicly confirmed the incident but has filed notification with the Vermont Attorney General. Affected individuals should monitor credit reports and watch for official notification letters.

CompanyASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C
IndustryHealthcare
Data Types ExposedPatient Names and Contact Information, Dates of Birth, Social Security Numbers, Health Insurance Information, Medical Diagnosis and Treatment Records, Appointment and Visit History, Billing and Payment Account Details, Employee Personnel Records
People AffectedNot Publicly Disclosed
Attack MethodClaimed Data Theft/Extortion
Regulators NotifiedVermont Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Associated Gastroenterologists Data Breach?

Associated Gastroenterologists of Central New York, P.C. is a gastroenterology medical practice that provides digestive health care to patients across the central New York region. A threat actor group calling itself Booba Project has claimed responsibility for a cyberattack against the practice. According to the group’s own claims, roughly 70 GB of data was taken from the organization’s systems.

The specific timeline of the intrusion has not been publicly disclosed. As a result, it is unclear exactly when unauthorized access to the practice’s network first began or how long the attackers may have had access before the theft was discovered. Because this information comes from the threat group’s leak site rather than from the practice itself, many operational details remain unknown.

At this time, Associated Gastroenterologists of Central New York has not publicly confirmed the incident. Therefore, important facts such as the exact method of intrusion, whether ransomware was deployed alongside the data theft, and the scope of any forensic investigation have not been verified by the organization. This article will be updated if the practice issues an official statement or notification.

Who was affected?

Because the practice treats patients throughout central New York, the people potentially affected likely include current and former patients of the gastroenterology practice. In addition, employees whose personnel records were stored on the same network could also be affected.

The exact number of individuals impacted by this incident has not been publicly disclosed. Medical practices typically store data belonging to thousands of patients, so the scope could be substantial. However, until an official count is released, the precise number of affected records remains unknown.

It is also unclear whether minors were among the affected patients. Gastroenterology practices commonly treat patients of all ages, including children, which means pediatric records could potentially be part of the exposed data.

What Information Was Potentially Exposed?

Because this incident involves a healthcare provider, the data at risk likely includes highly sensitive personal and medical information. While the complete list of compromised data fields has not been confirmed by the practice, breaches involving medical practices commonly expose the following categories of information.

  • Patient names and contact information
  • Dates of birth
  • Social Security numbers
  • Health insurance information
  • Medical diagnosis and treatment records
  • Appointment and visit history
  • Billing and payment account details
  • Employee personnel records

If Social Security numbers and medical records were indeed included in the stolen data, affected individuals could face a heightened risk of identity theft. Criminals can use stolen Social Security numbers to open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. This type of fraud can take months to detect and even longer to resolve.

In addition, medical information carries its own distinct risks. For example, stolen health records can be used to commit medical identity theft, where someone else uses a victim’s identity to obtain treatment or prescriptions. This can lead to inaccurate information appearing in the victim’s own medical file, which may affect future care decisions. Because this data cannot be changed like a password, the exposure can create a lasting risk.

What is the company doing?

Associated Gastroenterologists of Central New York has not publicly confirmed this incident or described any specific response steps. As a result, details about remediation efforts, system restoration, or notification timelines are not currently available from the organization itself.

However, the practice has filed a formal data breach notification with the Vermont Attorney General. This filing indicates that at least some regulatory notification process is underway, even though the practice has not issued a broader public statement. Affected individuals should watch for direct notification letters, which often include details about any credit monitoring or identity protection services being offered.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should begin checking their credit reports regularly for signs of unfamiliar activity. You can request free credit reports from each of the three major credit bureaus and review them for new accounts you did not open.

Because fraud involving stolen Social Security numbers can take time to surface, consistent monitoring over the coming months is important. If you notice unfamiliar accounts or inquiries, report them to the credit bureau immediately and consider filing a dispute.

Consider a Fraud Alert or Credit Freeze

If Social Security numbers or financial details were part of this breach, placing a fraud alert on your credit file is a smart precaution. A fraud alert requires lenders to take extra steps to verify your identity before opening new credit in your name.

For stronger protection, you might also consider a credit freeze. This restricts access to your credit file entirely, making it much harder for identity thieves to open new accounts. Although a freeze requires a few extra steps when you need credit yourself, it offers one of the most effective defenses available.

Protect Against Medical Identity Theft

Because medical records may have been exposed, it is wise to request a copy of your medical records and insurance claims history from your providers. Look carefully for any treatments, prescriptions, or services you do not recognize.

If you find discrepancies, contact your healthcare provider and insurance company right away. In addition, keep a record of all communications in case you need to dispute fraudulent claims later.

Stay Alert for Phishing Attempts

After a healthcare data breach, scammers often send phishing emails or text messages pretending to be from the affected practice or a related insurance provider. These messages may try to trick you into revealing additional personal information.

Therefore, never click on links or provide personal details in response to unsolicited messages. Instead, verify any communication directly with the practice using a phone number you already know is legitimate.

Consult a Data Breach Attorney

Given the sensitive nature of the data potentially involved, affected individuals may want to speak with a data breach attorney. An attorney can help determine whether you qualify for compensation through a class action or individual claim.

Many attorneys offer free consultations for data breach cases, so there is little downside to getting informed. This step can help you understand your legal options as more details about this incident become available.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from Vermont Attorney General

Related Data Breaches

Check other recent data breach notifications →