Bolton Street Pediatrics
| Primary URL | Location | Industry | www[.]boltonstreetpediatrics[.]com |
Country
United States of America
|
Healthcare
|
|---|
Profile
Bolton Street Pediatrics operates as a medical practice that focuses on the health care of infants, children, and adolescents. The organization's name indicates its specialization in pediatrics, which involves providing preventive care, diagnosing and treating illnesses, and monitoring growth and development for younger patients. It is headquartered in the United States, where it serves the local community surrounding Bolton Street. As a pediatric provider, the organization collects and maintains a range of personal health information, including vaccination records, developmental assessments, and treatment histories. This data is subject to federal privacy regulations such as the Health Insurance Portability and Accountability Act, which governs how health care entities must protect patient information. The practice likely employs physicians, nurses, and administrative staff who are trained in child‑specific medical care and patient communication.
Bolton Street Pediatrics came to public attention in February 2021 when it fell victim to a ransomware attack conducted by the Pysa threat actor group. The attackers gained access to the organization's network, exfiltrated sensitive data belonging to more than 1,000 patients, and then encrypted files on the compromised systems. The stolen information reportedly included medical histories and Social Security numbers, highlighting the types of data that pediatric practices routinely handle. Pysa is known for targeting health care and educational entities and for publishing the stolen data of victims who do not pay the ransom on a dark‑web leak site. Despite clear evidence of the breach, Bolton Street Pediatrics did not issue a public disclosure or notify the affected individuals, a response that differed from several peer health care organizations that reported the incident to regulators and provided patient notifications. The incident underscores the importance of robust cybersecurity controls for organizations that manage sensitive health information, particularly those serving vulnerable populations such as children. No additional details regarding the organization's size, ownership structure, or parent‑subsidiary relationships are available in the source material.
