CSIDB logo
Incident

Family Practice Center

Incident posture

Attack window
Oct 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-22 00:00

Linked entities

Victim
Family Practice Center
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A healthcare provider experienced a cybersecurity incident involving unauthorized access to patient information, including names, addresses, medical insurance details, and treatment-related data, with a limited subset of individuals’ Social Security numbers also compromised. While medical records remained unaffected, the organization engaged independent cybersecurity experts to bolster protections and initiated written notifications to potentially impacted individuals. A dedicated call center was established to address patient inquiries regarding the breach and mitigation steps.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Family Practice Center (FPC) experienced a cybersecurity incident involving unauthorized access to patient information, discovered on or around October 11, 2021. The breach exposed sensitive personal and health-related data, though FPC confirmed patient medical records were not compromised. Affected information included patient names, addresses, medical insurance details, and health/treatment information. A limited subset of individuals also had Social Security numbers exposed. FPC conducted an investigation but found no evidence that the accessed information had been misused. The organization delayed full notification until June 30, 2022, when it finalized current address information for impacted individuals to facilitate written communications. The incident did not disrupt clinical operations or compromise core medical record systems, but it created potential risks of identity theft or insurance fraud for affected patients.

In response, FPC engaged independent cybersecurity professionals immediately after discovery to strengthen protections and prevent future unauthorized disclosures. The organization initiated a notification campaign by mail to all potentially impacted individuals, detailing the nature of the breach and recommended protective steps. FPC established a dedicated toll-free call center operational Monday through Friday from 9:00 a.m. to 9:00 p.m. Eastern Time (1-833-909-4308) to address patient inquiries. Notification letters included specific guidance for monitoring personal information, particularly for those whose Social Security numbers were exposed. The breach response focused on transparency and risk mitigation, though FPC did not disclose technical details about the attack vector or the duration of unauthorized access prior to detection. All containment and remediation efforts were completed internally without regulatory penalties or publicized legal actions stemming from the incident.

Sources

Sources available to members: 1 source.

CSIDB