-
A forum user claims to have pulled 1.7 million health worker records through a Rofim Doctor API.
-
A review of the sample data suggests the records might come only from France’s public health directory. No patient or user data appears to be in the list.
-
The real issue may be bulk access, not secrecy. Nobody has confirmed whether the API let anyone download records in large numbers.

Alleged data tied to Rofim Doctor, a telemedicine platform based in Marseille, appeared on a popular cybercriminal forum on October 1, 2026. The poster described the dump as a database containing 1.7 million user records. They also attached a sample of 1,000 records as proof. None of this has been independently verified.
Rofim lets doctors and other clinicians ask colleagues for remote expert opinions. Its signup process checks each user’s RPPS number. That is France’s permanent ID number for health professionals.
How the Actor Says It Worked
The poster who uses the handle “Quantique” claimed they found the access while testing how Rofim validates RPPS numbers during signup. After this step, the site asks the server for corresponding professionals via a request to the API. According to the actor, the server fetched results page by page, which made the bulk data collection possible.
A screenshot in the post provides a structured response featuring several individuals, together with pages for each. Breach monitoring website FrenchBreaches evaluated the post and marked the information as credible. The breach notification service HackNotice also logged it.
What the Sample Contains
The sample lists names, RPPS numbers, professions, specialties and cities. Some records even come with extra details, like a phone number or a FINESS number, which tags a health facility. You’ll find doctors, dentists, pharmacists, midwives, nurses, and physiotherapists on these lists.
FrenchBreaches found no patient files in the sample. It also saw no diagnoses, prescriptions, passwords, bank details or birth dates. That separates this case from many healthcare breaches, which involve medical records.
Rofim’s Response
Rofim has not issued any statement regarding the alleged leak. But the 1.7 million entries appear to come from the public health directory run by ANS, France’s digital health agency.
This directory is publicly accessible. This organization also makes available several downloadable databases containing the names, RPPS number, profession, specialties, and workplace of the individuals. So much of what the actor posted could be gathered legally.
Is the Forum Claim Really a Leak?
FrenchBreaches divides the problem into two parts. First, was there any vulnerability that allowed for an API query in such large quantities? Second, was the retrieved information private? In most cases, the answer to the latter is probably not.
An API created to allow individual queries at the time of signup should never return a whole directory at once. Even if the information is public, such bulk access indicates a possible design flaw. Rofim has not said whether it has limited or changed the API.
Incidents such as this happen a lot. Scrapers collect public records and dump them online, calling them breaches. But just because it’s public doesn’t mean there’s no risk it just shifts the type of risk.
Take phone numbers, for example. Work numbers are often easy to find, but personal numbers? Not always. That’s harder to figure out. You can’t tell just by looking at a small sample. You’d have to compare everything side by side with the official records to really know what’s at stake.
There is much that remains unclear:
- Does the actor actually have all 1.7 million records?
- There’s a need to verify how many unique individuals are in the database. One person could appear multiple times if they worked in multiple locations.
- Are any of the phone numbers in the dataset private?
- What restrictions did the API normally enforce
- Whether there are additional fields apart from the ones in the sample.
The 1.7 million record total could be an overstatement of the actual number of affected individuals.
Why the Leak is Still Risky
Data publicly available may still be misused. A separate healthcare incident also saw patient information appear on the dark web, where patient data from the Doctor Alliance breach allegedly appeared. Once the list of connections between names, RPPS numbers, and phone numbers comes up, it is all good for fraudsters. It offers sufficient grounds to pose as hospitals, insurance companies, or coworkers and target busy people.
Also, the RPPS number connects to secure services. Rofim’s own guide associates the number with digital identity services like e-CPS and Pro Santé Connect. Though the number itself is not the password for anything, it still is a great starting point for attacks.
Trust is also important here. Rofim handles transactions between clinicians, and the listing shows it uses a host authorized to process health data in France.
Healthcare employees should always be careful about unexpected calls and emails related to their RPPS number. Never share any login codes; check all requests via contacts you already know.
What’s Next
Rofim’s next move will matter most. The company needs to explain how their API worked. Did they stop bulk access? Was any private info actually exposed? Until we get answers, this doesn’t feel like a stolen medical database, just a public directory that was way too easy to scrape.