CSIDB logo
Threat actor

Bizmatics, Inc.

Attribution profile

Type
Criminal
Location
United States of America
Known incidents
2 incidents
First seen
2015-01-01
Last seen
2015-01-01
Updated
2026-08-28 17:33
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Bizmatics, also referred to as Bizmatics, Inc., is a threat actor identified in public breach reports. The entity is associated with the United States of America as its known location. It operates as a third‑party medical software vendor that provides services to healthcare organizations. The alias “Bizmatics” appears consistently across the cited sources describing the incidents.

The publicly reported activity of Bizmatics involves the healthcare sector, specifically eye care, podiatry, and family foot care practices. All identified victims are located within the United States, with incidents reported in Florida and Illinois. The actor’s targeting appears limited to organizations that rely on its software for patient management and billing. No additional sectors or geographic regions are mentioned in the available sources.

The sources do not describe any specific malware families, exploit tools, or initial access vectors used by Bizmatics. Consequently, no detailed TTP profile can be constructed from the supplied information. Attribution to a state sponsor, criminal consortium, or other organized group is not publicly established in the reports. The breach reports note that unauthorized individuals accessed patient data through the vendor’s systems, leading to the exposure of names, addresses, Social Security numbers, dates of birth, telephone numbers, and insurance details. Representative incidents include the 2015 breach affecting a Florida‑based eye care provider that compromised over 87,000 records. A second 2015 incident involved the Illinois Valley Podiatry Group, where 26,588 patient records were accessed via the same contractor. A related case concerning Complete Family Foot Care, impacting approximately 5,883 patients, was also mentioned but not formally attributed to the vendor in federal breach filings. Post‑breach actions described in the sources include the vendor reinforcing firewall and network configurations and the affected providers discontinuing the software. Affected individuals were offered identity protection and credit monitoring services for one year in the Florida case. These events constitute the currently documented operational history of Bizmatics as a threat actor.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB