Cyber Incident Victim: Adventist Health
Date:
Dec 2023
Location:
United States of America
Summary
Dameron Hospital experienced a cyberattack disrupting certain network systems, prompting an investigation with external cybersecurity experts. Patient care operations continued normally, including emergency services, though some procedures were rescheduled during the transition to established downtime protocols to ensure seamless care continuity at the nonprofit community facility serving San Joaquin County.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Dameron Hospital in Stockton experienced a cyberattack that disrupted operations in late November or early December 2023, prompting an investigation into the data security incident. The hospital confirmed on December 1, 2023, that the attack impacted certain network systems, though it did not specify the exact date of intrusion or identify compromised systems. Upon detection, the hospital's internal team immediately initiated incident response protocols to secure affected infrastructure while maintaining critical patient care services. External cybersecurity experts were engaged to assist with forensic analysis and containment efforts. The organization activated established system downtime procedures to sustain healthcare delivery during network disruptions, with its emergency department continuing normal operations throughout the incident.

The cyberattack caused operational disruptions that required rescheduling of some patient procedures during the transition to backup systems. Hospital administrators prioritized continuity of care by delaying non-urgent treatments until contingency plans were fully implemented. As a nonprofit community hospital with over 200 beds serving San Joaquin County residents, Dameron maintained transparency about service adjustments while withholding technical details about the attack vector or potential data exposure. No ransomware claims or threat actor attributions were disclosed in initial statements. The investigation remained ongoing as of the December 1 public notification, with no reported timeline for full system restoration or completion of the security review.
