Skip to content
June 20, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • MEDantex Transcription Service data leaks
  • Data Leak

MEDantex Transcription Service data leaks

Do Son April 27, 2018 3 minutes read
Add as a preferred
source on Google

MEDantex is a medical transcription company headquartered in Kansas, USA. Its main business is to provide customized transcription solutions for hospitals, clinics, and private doctors. Last week, KrebsOnSecurity, a well-known security website, sent a notice to the company saying that an online portal of the company exposed the patient’s medical records and involved more than a thousand doctors.

The so-called medical transcription refers to the use of word processing software to transcribe information recorded in the medical process according to the doctor’s dictation recording. This may include records of medical records, physical examination reports, clinical diagnosis, surgical reports, X-ray reports, and pathology. Transcription of reports and other information.

Medical transcription can be said to be one of the fastest growing areas in the healthcare industry. In Western countries, especially countries such as the United States where the entire healthcare industry is based on insurance and detailed medical records, this service allows doctors to dictate patient records over the phone and get edited texts in a short period of time. file.

KrebsOnSecurity learned last Friday (April 20th) that a portal site owned by MEDantex had the potential to leak medical records from patients. The site allows doctors to upload audio files, which are the dictation tapes we mentioned earlier that need to be transcribed. This feature page should have been originally encrypted, but it turns out that any Internet user can access it.

What’s more, the online tool pages used by many MEDantex employees are also completely open to Internet users, including pages for adding or removing user accounts, and pages that can search for patient medical records by the doctor or patient name, while accessing all these pages does not require authentication.

Not only that, KrebsOnSecurity also believes that MEDantex may have become a victim of ransomware called WhiteRose. Sreeram Pydah, founder, and CEO of MEDantex, confirmed that the company did experience a ransomware infection and recently rebuilt the online server.

Pydah said that the site has been closed for about two weeks, but the security threats notified by KrebsOnSecurity seem to have been incorporated into the reconstruction process in some way. In other words, after the site was rebuilt, the problem of patient medical records exposure still exists.

KrebsOnSecurity said that it is not yet clear how many patients’ medical records were exposed on the MEDantex website, but one of the catalogs named “/documents/userdoc” contains documents relating to more than 2,300 doctors. The catalogs are arranged in alphabetical order. Each catalog contains a different number of patient medical records. Both the Microsoft Word document and the original audio file can be downloaded.

Although many of the documents seem to have only recently been created, some of these records date back to 2007. It is also not clear at the time when these documents were initially exposed, but according to Google’s cache, the site page appears to have been publicly accessible since April 10, 2018.

It is worth noting that if these medical records are leaked, the impact will be enormous. According to the information displayed on the MEDantex official website, the customers of its transcription service are almost covered by the entire United States, including New York University Langney Medical Center, San Francisco Multidisciplinary Medical Group, Jackson Hospital in Montgomery, Alabama, Allen County Hospital in Iola, Kansas, Green Clinic Surgical Hospital in Ruston, Los Angeles, Trillium Specialist Hospital in Mesa, Arizona and Sun City, Cooper University Hospital in Camden, NJ, Sunrise in Miami The Medical Group, the Wichita Clinic in Wichita, Kansas, the Kansas Spine Center, the Kansas Plastic Surgery Center, and the basic surgical hospitals throughout the United States.

Related coverage

  • 55 Million Records: Thailand’s PII Massive Leak Unveiled
  • Pan-American Life Insurance Group Hit by Data Breach
  • Privacy Fail: Grok Chatbot Exposes 370,000 Private Conversations
  • Riot Games has been hacked: League of Legends and other game source codes stolen
  • Activision Blizzard is suspected of leaking sensitive employee information and game data

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: MEDantex Transcription Service

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-11551CVSS 9.8
    The Branda plugin for WordPress is vulnerable to privilege escalation via account...
  • CVE-2026-56081CVSS 9.1
    Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker...
  • CVE-2026-56073CVSS 9.4
    Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that...
  • CVE-2026-55447CVSS 9.6
    ### Summary All components based on `BaseFileComponent` are vulnerable to the following...
  • CVE-2026-48584CVSS 9.9
    Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to...
  • CVE-2026-48582CVSS 9.6
    Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
  • CVE-2026-45480CVSS 10.0
    Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate...
  • CVE-2026-55255CVSS 9.9
    ## Summary Insecure Direct Object Reference (IDOR) vulnerability in `/api/v1/responses` endpoint allows...
  • CVE-2026-54782CVSS 10.0
    ### Impact Full impersonation of any principal the trusted STS could have...
  • CVE-2026-48773CVSS 9.8
    ProxySQL is a proxy for MySQL and its forks, as well as...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.