Mix NEW: 2.1 million personal medical records from AP-HP (Paris hospitals)

Mix NEW: 2.1 million personal medical records from AP-HP (Paris hospitals)

graycat

User
User ID
140577
Dec 16, 2025
1
1
#CR
8
  • Thread starter
  • Thread Author
  • #1
We are proud to announce the compromise of 2.1 million patient records from AP-HP (the public hospital system of the Paris region).

This operation spanned four years and required access to dozens of different service and hospital accounts. As a result, the medical records date back to 2021 for the oldest and up to 2025 for the most recent.

By gaining access to physician and healthcare staff accounts across all hospitals in the region, we were able to scrape data from ORBIS, the internal patient record management tool, which contains all medical and social data. The patient information necessary for scraping was obtained through the accounting department's data.
Here are the types of data involved, per patient:

Identité / DMB / Social / Rééducation / Avis / Soins / Médicaments / RDV / Réanimation / Urgences adultes / Urgences pédiatrique / Imagerie / Prescription biologique / Résultat biologique / Périnatal / Anesthésie / PMSI MCO / PMSI SSR / PMSI actes / NGAP / PMSI PSY / PMSI SIM / CPOE / SIU

During the scraping process, the software was enhanced with additional features and interconnectivity. Therefore, some records may not contain all of these data points. We downloaded as much data as possible for each patient.

AH-HP can reach out to us privately. We will transfer all the data in our possession immediately. And then we will negotiate.

We would not like to have to publish the medical records of sick and innocent people, but we are not responsible for the poor security of their system. We are giving them 14 days to consider. After this deadline, the records will be published here for free, at a rate of 100,000 records per day, totaling 7 TB of data.
 
Thanks for sharing.

To better assess the credibility of this claim, can you clarify a few points:

• Can you provide non-sensitive samples (redacted) demonstrating the structure of the data (field names, timestamps, formats), without exposing personal data?
• Which specific AP-HP entities / hospitals were involved (ORBIS instance scope, single GHU vs regional)?
• Is this data coming from a single database export or multiple sources aggregated over time?
• How do you distinguish this dataset from the known 2020–2021 AP-HP COVID data breach already publicly documented?
• Are the records internally consistent (patient IDs, visit dates, medical acts) across years 2021–2025?

Clarifying these points would help differentiate a genuine breach from recycled or recomposed datasets.
 
Back
Top Bottom