Doctor Alliance – Streamlined Document and Billing Management for Healthcare Providers Listed by kazu Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Doctor Alliance has been listed by the kazu ransomware group, which claims to have exfiltrated internal files. The incident was disclosed on 13 November 2025; an undisclosed number of individuals may be affected, and anyone connected to the organisation should review their exposure and take protective steps.
Doctor Alliance, a U.S. healthcare technology platform based in Dallas, Texas, was listed by the ransomware group kazu on November 13, 2025. Public details confirm only that the group claims to have exfiltrated internal files in a ransomware attack against the company, which operates doctoralliance.com and provides document, referral, and billing management tools for physicians and medical agencies. The number of people affected remains unknown, and no further verified information about the scope or method of the incident has been released.
This matters because Doctor Alliance handles sensitive operational data for healthcare providers, including materials tied to patient care coordination and billing. Any unauthorized access to such systems raises practical concerns for the medical practices that rely on the platform and for the individuals whose information may flow through it.
Inside the incident
According to the available record, the ransomware group kazu listed Doctor Alliance on its leak site on November 13, 2025. The listing asserts that internal files were exfiltrated during a ransomware attack. No public confirmation of the attack method, the precise date of intrusion, the volume of data taken, or any ransom demand has been disclosed. The number of individuals potentially affected is listed as unknown. The only concrete claim attached to the listing is the exfiltration of internal files, accompanied by language typical of such postings that invites contact to protect the files. Beyond this claim, independent verification of the breach details remains limited.
Doctor Alliance has not issued a public statement that is reflected in the current facts, and no additional technical indicators or timelines have been released. As with many ransomware listings, the group’s assertion stands as an unverified claim until corroborated by the organization or independent investigators.
The group behind it: kazu
Kazu is a ransomware operation that follows the now-common double-extortion model: encrypting systems while also stealing data and threatening to publish it if payment is not made. Like other groups in this category, kazu maintains a leak site where it posts victim names and sample claims of stolen material to apply pressure. Public reporting on kazu has documented its focus on a range of sectors, including healthcare and professional services, with tactics that typically involve initial access through phishing, compromised credentials, or unpatched remote services, followed by lateral movement and data staging before encryption.
The group’s listings are claims rather than What's Publicly Reported. In this case, the appearance of Doctor Alliance on the kazu site is presented solely as the group’s assertion that internal files were taken. No specific statements by kazu about the contents of those files, the size of the haul, or any unique demands related to this victim have been recorded beyond the generic leak-site language. Established patterns show that such groups often exaggerate or selectively release material, so the listing itself does not constitute proof of the full extent of any compromise.
Doctor Alliance and its sector
Doctor Alliance is a healthcare technology company headquartered in Dallas, Texas. It offers a platform that consolidates document management, electronic signing, referral coordination, and billing support for physicians and medical agencies. Services include tools for programs such as Care Plan Oversight (CPO), Chronic Care Management (CCM), and Transitional Care Management (TCM), along with integrations to systems like Axxess Home Health. The stated purpose is to reduce paperwork, speed document turnaround, and improve billing efficiency for home-health and related providers.
Organizations of this type sit at the intersection of clinical operations and administrative finance. They routinely process referrals, signed clinical documents, billing records, and coordination data that link providers, agencies, and payers. A breach involving such a platform is consequential because the data often includes identifiers and operational details that, if exposed, can affect both the medical practices that depend on the service and the patients whose care is documented through it. Healthcare technology vendors are frequent targets precisely because of the concentration of sensitive administrative and clinical information they hold.
What data was at risk
The facts state only that internal files were exfiltrated in a ransomware attack. No specific categories—such as patient records, billing details, employee information, or credentials—have been named or confirmed. Exact contents remain unconfirmed.
Platforms like Doctor Alliance typically store electronic documents, referral forms, signed clinical notes, billing submissions, and related administrative files. These materials can contain names, contact details, medical identifiers, insurance information, and provider credentials. Because the public record does not enumerate what was taken, it is not possible to state with certainty which of these data types, if any, were included in the claimed exfiltration. The only verified description is the generic reference to internal files.
The real-world impact
For individuals whose information may have passed through Doctor Alliance systems, the primary risks are identity-related misuse and targeted phishing. Even limited internal files can contain enough personal or medical identifiers to enable fraudulent claims, account takeovers, or social-engineering attempts that reference genuine care details. Because the number of affected people is unknown and the precise data types are undisclosed, the scale of any individual exposure cannot be quantified at present.
For the organization and its customers—physicians and medical agencies—the consequences include potential disruption of document workflows, temporary loss of access to billing tools, and the administrative burden of notifying partners and investigating the claim. Healthcare providers that rely on the platform may face delays in referrals or claims processing while systems are reviewed. Reputational and contractual obligations to protect health-related data add further operational pressure, regardless of whether the full extent of the claimed exfiltration is later confirmed.
If your data was in this claimed breach
If you are a physician, agency staff member, or patient who has interacted with Doctor Alliance services, begin by monitoring financial and medical accounts for unusual activity. Place fraud alerts with the major credit bureaus if you believe personal identifiers may have been involved, and be cautious of unsolicited communications that reference medical documents or billing. Change passwords on any accounts that reused credentials associated with the platform, and enable multi-factor authentication wherever available.
Because the exact contents of the claimed file set remain unconfirmed, treat any notification from Doctor Alliance or its customers as the authoritative source of guidance. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in other known breach data sets; this provides an independent baseline while official details continue to develop.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ManageMyHealth - New Zealand Listed by kazu Ransomware GroupzHealthEHR — Practice Management Software for Chiropractic & Wellness Clinics Listed by kazu Ransomware GroupCT Dent Ltd Listed by kazu Ransomware GroupNational Civil Service Commission of Colombia Listed by kazu Ransomware GroupLatest breaches
Publicly posted by kazu — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.