Skip to content
September 29, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Data Leak
  • MEDantex Transcription Service data leaks
  • Data Leak

MEDantex Transcription Service data leaks

Do Son April 27, 2018 3 minutes read
Add Daily CyberSecurity as a preferred source on Google

MEDantex is a medical transcription company headquartered in Kansas, USA. Its main business is to provide customized transcription solutions for hospitals, clinics, and private doctors. Last week, KrebsOnSecurity, a well-known security website, sent a notice to the company saying that an online portal of the company exposed the patient’s medical records and involved more than a thousand doctors.

The so-called medical transcription refers to the use of word processing software to transcribe information recorded in the medical process according to the doctor’s dictation recording. This may include records of medical records, physical examination reports, clinical diagnosis, surgical reports, X-ray reports, and pathology. Transcription of reports and other information.

Medical transcription can be said to be one of the fastest growing areas in the healthcare industry. In Western countries, especially countries such as the United States where the entire healthcare industry is based on insurance and detailed medical records, this service allows doctors to dictate patient records over the phone and get edited texts in a short period of time. file.

KrebsOnSecurity learned last Friday (April 20th) that a portal site owned by MEDantex had the potential to leak medical records from patients. The site allows doctors to upload audio files, which are the dictation tapes we mentioned earlier that need to be transcribed. This feature page should have been originally encrypted, but it turns out that any Internet user can access it.

What’s more, the online tool pages used by many MEDantex employees are also completely open to Internet users, including pages for adding or removing user accounts, and pages that can search for patient medical records by the doctor or patient name, while accessing all these pages does not require authentication.

Not only that, KrebsOnSecurity also believes that MEDantex may have become a victim of ransomware called WhiteRose. Sreeram Pydah, founder, and CEO of MEDantex, confirmed that the company did experience a ransomware infection and recently rebuilt the online server.

Pydah said that the site has been closed for about two weeks, but the security threats notified by KrebsOnSecurity seem to have been incorporated into the reconstruction process in some way. In other words, after the site was rebuilt, the problem of patient medical records exposure still exists.

KrebsOnSecurity said that it is not yet clear how many patients’ medical records were exposed on the MEDantex website, but one of the catalogs named “/documents/userdoc” contains documents relating to more than 2,300 doctors. The catalogs are arranged in alphabetical order. Each catalog contains a different number of patient medical records. Both the Microsoft Word document and the original audio file can be downloaded.

Although many of the documents seem to have only recently been created, some of these records date back to 2007. It is also not clear at the time when these documents were initially exposed, but according to Google’s cache, the site page appears to have been publicly accessible since April 10, 2018.

It is worth noting that if these medical records are leaked, the impact will be enormous. According to the information displayed on the MEDantex official website, the customers of its transcription service are almost covered by the entire United States, including New York University Langney Medical Center, San Francisco Multidisciplinary Medical Group, Jackson Hospital in Montgomery, Alabama, Allen County Hospital in Iola, Kansas, Green Clinic Surgical Hospital in Ruston, Los Angeles, Trillium Specialist Hospital in Mesa, Arizona and Sun City, Cooper University Hospital in Camden, NJ, Sunrise in Miami The Medical Group, the Wichita Clinic in Wichita, Kansas, the Kansas Spine Center, the Kansas Plastic Surgery Center, and the basic surgical hospitals throughout the United States.

Related coverage

  • Avast Privacy Breach: FTC Refunds Open Until June 2025
  • Reddit Data Breaches: Emails, Passwords leaked
  • Taiwan Warns Public: Popular Chinese Apps (TikTok, WeChat, Rednote) Pose National Security Risk Via Data Transfer to China
  • Intel OEM Private Key Leak: A Blow to UEFI Secure Boot Security
  • Over 10 million Malaysian citizenship information was leaked due to SQLi bug
  • NB65 leaked the Kaspersky antivirus source code
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: MEDantex Transcription Service

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-69431CVSS 9.8
    Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 29, 2026
  • CVE-2026-7192CVSS 9.3
    A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause...
    📅 Updated: Sep 29, 2026
  • CVE-2026-22094CVSS 9.3
    The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as...
    📅 Updated: Sep 29, 2026
  • CVE-2026-102268CVSS 9.1
    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected...
    📅 Updated: Sep 29, 2026
  • CVE-2026-100818CVSS 9.6
    Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4,...
    📅 Updated: Sep 29, 2026
  • CVE-2025-15039CVSS 9.4
    The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when...
    📅 Updated: Sep 29, 2026
  • CVE-2026-6928CVSS 9.8
    IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker...
    📅 Updated: Sep 29, 2026
  • CVE-2026-92035CVSS 9.6
    Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156,...
    📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.