Cyber Incident Victim: All About Potential Family Chiropractic
Date:
Feb 2020
Location:
United States of America
Summary
A chiropractic practice in South Dakota, All About Potential Family Chiropractic, experienced a cyberattack by the Maze Team, which resulted in unauthorized access and data exfiltration. The attackers publicly released sample files containing protected health information, including patients' full names, service dates, diagnoses, treatment details, and explanation of benefits statements, alongside employment-related documents and dietary records. Despite the exposure of sensitive data, the threat actors inaccurately listed the victim as RamTek on their platform. The practice had not issued a public statement or disclosed the scope of affected records at the time of initial reporting, with no response provided to inquiries about the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On or around February 5, 2020, the Maze ransomware group publicly claimed responsibility for a cyberattack targeting All About Potential Family Chiropractic, PC, a South Dakota-based practice operated by Drs. Scott and Dawn Hourigan. The attackers exfiltrated and subsequently dumped sample data from the chiropractic office's servers as part of their established pattern of naming victims and releasing stolen information. Analysis of the leaked data by cybersecurity observers revealed a diverse collection of compromised files, including employment records, dietary documents, and protected health information (PHI) belonging to patients. The exposed PHI contained sensitive details such as patients' full names, dates of service, medical diagnoses, treatment types, and explanation of benefits (EOB) statements. Maze inaccurately listed this victim as "RamTek" on their leak site despite the clear identification of the actual chiropractic practice in the stolen records.

The incident exposed significant volumes of sensitive patient data with no immediate public clarification from Maze regarding the total number of affected individuals or files. The compromised health information created risks of medical identity theft, insurance fraud, and privacy violations for patients. At the time of public reporting, All About Potential Family Chiropractic had not posted any breach notifications on their website or responded to media inquiries from DataBreaches.net, which had submitted detailed questions about the attack earlier on February 5. The absence of confirmed containment measures, detection methods, or remediation steps by the practice left the full scope of operational disruption and long-term consequences undocumented in available sources. Maze's data dump demonstrated their capability to access and extract heterogeneous organizational data, emphasizing the vulnerability of small healthcare entities to coordinated ransomware operations.
