Menu
Browse

Cyber Incident Victim: Hendrick Health System

Date:

Oct 2020

Location:

United States of America

Summary

A healthcare provider experienced a network security breach that potentially exposed patient information including names, Social Security numbers, demographic details, and limited care-related data, though electronic health records remained unaffected. The incident disrupted computer operations at certain facilities while leaving others untouched, with unauthorized access occurring over approximately one month before detection. The organization initiated patient notifications following an investigation but the event did not appear on federal breach reports or ransomware leak platforms at the time of disclosure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Hendrick Health System identified a network security breach on November 20, 2020, following unauthorized access to its computer systems between October 10 and November 9 of that year. The organization determined that patient information exposed during the incident included names, Social Security numbers, demographic details, and limited information about care provided at their facilities. Electronic health records systems remained unaffected by the breach, preserving the integrity of core medical documentation. The security incident specifically impacted operations at Hendrick Medical Center and Hendrick Clinic, while Hendrick Medical Center South and Hendrick Medical Center Brownwood systems were not compromised. Hendrick initiated patient notifications regarding the data exposure beginning October 10, 2020, through public statements and direct communications, though the breach had not yet appeared on official HHS breach reporting tools at the time of reporting.

Cyber Incident Image

The breach caused operational disruptions across affected facilities, necessitating system containment measures during the investigation period. Forensic analysis confirmed the exposure window spanned approximately one month before detection, though no evidence emerged suggesting the compromised data appeared on ransomware leak sites operated by cybercriminal groups. Hendrick maintained transparency through public disclosures on their official website starting in November 2020, prior to formal regulatory notifications. The organization focused notification efforts on individuals whose sensitive personal information was potentially accessible during the intrusion, while confirming unaffected facilities continued normal operations throughout the incident period. System recovery efforts proceeded concurrently with ongoing investigations to determine the full scope of impacted data and systems.

Sources
Sources available to members
1 source