Researchers from vpnMentor discovered a breach of databases operated by xSocialMedia, a Facebook marketing agency focusing on campaigns for medical malpractice lawsuits. The approximately 150,000 personal records on users, including US Veterans, comprised of medical data and deeply personal medical testimonies, identifying information, contact information, invoice records, and campaign metrics. The leaked health data may not be covered by the HIPAA Privacy Rule since patients are free to disclose their health information to the parties of their choice. In this case, they submitted health information into a form on the website; however, there is a reasonable expectation of privacy to not publicly expose or link the data to their identities. xSocialMedia was informed about the breach twice before responding and closing the database. More information about this breach can be found in the vpnMentor blog post.