Blossom Health Records on 29,600 Mental Health Patients Offered for Sale
A forum actor posting as 2019 is selling what they describe as the patient database of Blossom Health, a virtual psychiatric care platform in the United States that provides online therapy and medication management for conditions including anxiety, depression, ADHD, autism, bipolar disorder and OCD. The listing covers more than 29,600 patients and the stated fields include legal, preferred and middle names, date of birth, gender, phone number, email, full home address, the assigned provider and referring physician, first and last appointment dates, account status and tags, together with a complete billing layer: insurance payer, member, plan and group identifiers, copay amounts and policy subscriber details. It is offered as a one time sale in cryptocurrency. The claim is unverified.
▣Post details
!What the post claims
- More than 29,600 patients
- Legal and preferred names
- Middle and last names
- Dates of birth
- Gender
- Phone numbers and emails
- Full home addresses
- Assigned provider named
- Referring physician
- First appointment dates
- Last appointment dates
- Client since dates
- Current status and tags
- Billing type
- Insurance payer identifiers
- Insurance member identifiers
- Plan and group identifiers
- Copay amounts
- Policy subscriber details
- Subscriber address and birth date
◱Screenshot
☷Mapped techniques
The post describes no intrusion method. Both entries are inferred from the artefacts, not stated.
- Collection T1213 Data from information repositories Inferred Clinical scheduling fields and the insurance billing layer appear in one uniform row set, which points to an export from the practice management system rather than data assembled from several places.
- Exfiltration T1567 Exfiltration over web service Inferred The sample is published inline and the sale is arranged through messaging services. The route out of the environment is not described.
⚠Potential impact
With a psychiatric provider, being in the file is itself the sensitive fact. Membership discloses that a named person at a known address is in mental health treatment, which reaches employment, custody proceedings, insurance and immigration matters, and the provider, tag and appointment fields narrow the picture considerably further. The billing layer creates a second and separate harm: insurance member, plan and group identifiers support medical identity theft and fraudulent claims, a form of fraud victims usually discover only when a bill or a denial arrives. The population also deserves care in how this is reported, since some of these people are currently unwell, and extortion or exposure threats aimed at psychiatric patients carry obvious risk.
iStatus Unverified
The sample is long and internally consistent, with real insurer names, member identifier formats that match those carriers' conventions, and addresses whose city, state and postal code agree, which is difficult to fabricate across many rows. What is missing is any account of how the data was obtained, with no method, no date and no indication whether access has been closed. The account is established with high standing, and the one time sale framing limits circulation while implying a single buyer with a specific use. Dark Web Informer has not retrieved the data and is not linking the contact addresses, and Blossom Health has not publicly addressed the claim.
Dark Web Informer // Threat Intelligence