CSIDB logo
Incident

Longs Peak Family Practice

Incident posture

Attack window
Nov 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-10 17:55

Linked entities

Victim
Longs Peak Family Practice
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Longs Peak Family Practice experienced a ransomware attack and subsequent unauthorized network intrusions, prompting immediate investigation and network security measures. Forensic experts confirmed hackers accessed parts of the system, though no specific evidence indicated patient data was viewed or exfiltrated. Malicious software installed during the incidents encrypted files and posed potential data exfiltration risks, creating uncertainty regarding health information compromise. The practice restored operations using secure backups but could not definitively rule out unauthorized access to protected health records due to the malware's capabilities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Longs Peak Family Practice, PC (LPFP) detected unauthorized hacking activity on November 5, 2017, triggering an immediate internal investigation and network security measures. Before LPFP could fully contain the intrusion, the attacker deployed malicious code including ransomware that encrypted files on the practice's computers. The organization relied on a separate secure backup of patient files to rebuild and restore its network infrastructure. Five days after the initial incident, on November 10, LPFP discovered a second unauthorized network intrusion that did not involve ransomware encryption. This second breach prompted the engagement of a specialized forensic firm to conduct a comprehensive investigation into both incidents, identify malware presence, and determine potential unauthorized data access.

The forensic investigation concluded on December 5, 2017, confirming unauthorized access to portions of LPFP's computer systems on November 5, 9, and 10. While investigators found no direct evidence that patient health information was accessed, copied, or removed from the network, they identified hacker-installed software capable of file exfiltration. The ransomware component had encrypted certain system files, creating uncertainty about whether health data might have been compromised during the encryption process or through other malicious tools. LPFP's examination confirmed no evidence of attackers opening patient files on their computers during the intrusion periods. Based on the forensic findings and inherent limitations in completely ruling out data exposure, the practice initiated patient notifications by December 27, 2017, disclosing the potential risk to protected health information while emphasizing their successful network restoration from secured backups.

Sources

Sources available to members: 1 source.

CSIDB