Health Now Networks Data Breach (2017): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Health Now Networks Data Breach (2017) (reported March 25, 2017) exposed Dates of birth, Email addresses, Genders and Health insurance information belonging to roughly 322K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
The breach involved a database left accessible without apparent controls. Public reports at the time stated that the dataset contained hundreds of thousands of medical records together with operator notes on individuals’ health. No information has been released on how long the database remained exposed, the method by which access was obtained, or whether the data were copied or further distributed.
How a breach like this happens
Incidents involving exposed databases often stem from storage systems that remain reachable from the public internet because access controls were never applied or were later removed. In the health and telemarketing sectors, large volumes of contact and medical information are routinely collected and retained; when these records are placed in cloud or on-premise databases without authentication requirements, automated scanning tools can locate them. Once discovered, the contents can be downloaded in bulk before the exposure is noticed and corrected.
About Health Now Networks
Health Now Networks operated as a telemarketing service that handled health-related outreach. Organisations of this type routinely collect names, contact details, dates of birth, insurance information and details of medical conditions in order to conduct calls and maintain client lists. Because the data concern people’s health, any unauthorised release carries regulatory and personal implications beyond those associated with ordinary marketing lists.
What was likely exposed
The records that were reported as accessible included the following categories of information:
- Dates of birth
- Email addresses
- Genders
- Health insurance information
- IP addresses
- Names
- Personal health data
- Phone numbers
Public accounts also referred to operator notes on medical conditions. The precise contents of every record remain unconfirmed beyond these reported categories.
What's at stake
Individuals whose information appeared in the dataset face the possibility that their contact details and health information could be used for unsolicited calls, targeted scams or further attempts to obtain additional data. Health insurers and medical providers may also face follow-on inquiries or regulatory scrutiny. For the organisation, the incident created potential liability under health-data protection rules and required remediation of the exposed storage system.
If your data was in this breach
Anyone who believes their information may have been held by Health Now Networks should monitor statements from their health insurers and consider placing a fraud alert with credit-reporting agencies. Changing passwords on any associated email accounts and enabling multi-factor authentication reduces the chance that exposed addresses can be used for account takeovers. Readers can run a free exposure scan of their email address against known breach data to check whether their information appears in public listings of this or other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Netshoes Data Breach (2017)ai.type Data Breach (2017)Open CS:GO Data Breach (2017)B2B USA Businesses Data Breach (2017)Latest breaches
Read GalaxyWarden’s full analysis of the Health Now Networks Data Breach (2017) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.