Research · Medical clinics

Business data exposure briefing

The kinds of business data that are routinely stolen and resold, and what a business can check from the outside today.

Published 1 Aug 2026Reading time 5 minSector Medical clinicsBy LeakTrace

This briefing lists kinds of business data that are routinely stolen and resold, and sets out what a business can check from the outside. It is a reference list for July 2026, not a count of listings, and it does not name or identify any business or person.

How LeakTrace looks

Everything LeakTrace checks is external and passive. We read monitored breach databases for a business's email addresses, the public DNS and email settings that decide whether someone can send mail in its name, its public web pages, and look-alike domains registered against its name. We do not buy, download or redistribute stolen data.

Categories of business data to check for

Use the list to ask one practical question: which of these does your business hold, and where does it live?

  • Dental practice patient records
  • Home services provider customer records
  • Bookkeeping firm client lists
  • Property management tenant records
  • Real estate transaction records
  • Real estate closing files
  • Physiotherapy clinic patient files
  • Independent retailer customer databases
  • Payroll and HR exports
  • RIA wealth advisor client contact lists

Why it matters

American businesses and consumers reported $20.9 billion in losses to internet crime last year across more than a million complaints, and business email compromise alone accounted for $3.05 billion of it. Most of that fraud starts with something visible from outside the business: a staff login already in a breach database, or an email domain anyone can impersonate.

A category appearing in this list does not mean any specific business has been breached. It means that type of record is worth knowing the location of before somebody else asks.

What to do next

Review your access controls, backup posture, and third-party integrations. If any of the categories above match data your organization holds, confirm who can reach it and whether the logins that protect it have turned up in a breach elsewhere.

To see whether someone can send email that looks like it came from your domain, request your outside reading at /business/: we read your firm from outside, including the email records that decide whether mail in your name can be forged, and send the reading to a work email at your domain.

Methodology

LeakTrace research describes what can be read from outside across the firms we assess. No client is named and no engagement is described. Where a percentage appears, it describes the firms in our view, not a national census.

Weekly briefing distribution list
The week’s public disclosures that matter to owner-run firms.

We will add you to the distribution list. To come off it, email [email protected]. Privacy policy.