CSIDB logo
Incident

CareATC

Incident posture

Attack window
Jul 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-08-10 03:20

Linked entities

Victim
CareATC
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2021
Discovered
Jul 2021
Disclosed
Aug 2021
Resolved
Pending

Summary

DuPage Medical Group disclosed that a cyberattack and ensuing network outage exposed personal information of approximately 655,000 patients after threat actors gained access to parts of its network during the incident. A forensic investigation found that the compromised data could include names, contact details, diagnosis codes, procedure codes, treatment dates, and Social Security numbers for a subset of individuals, while no financial information was affected. All affected patients were offered free credit monitoring and identity theft protection, and the organization has since strengthened its security controls, reviewed policies, and is working with law enforcement on the ongoing investigation.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 13, 2021, DuPage Medical Group reported a security incident that disrupted its network systems. Investigation revealed that threat actors gained access to the network between July 12 and July 13. Upon discovery, DMG launched an investigation into the impact alongside a third‑party cyber‑forensic specialist firm. The forensic team conducted a review to assess whether patient information was affected. The review confirmed that the hackers had access to just certain portions of the network and the patient data stored on those systems.

The compromised data could include names, contact details, diagnosis codes, Current Procedural Terminology (CPT) codes tied to procedures, and treatment dates. Along with those elements, Social Security numbers for a subset of patients were also potentially exposed. No financial information was impacted by the breach. DuPage Medical Group began notifying 655,384 patients that their data was compromised during the cyberattack and network outage in mid‑July. With its breach tally, the DMG hack is among the ten largest incidents reported in the health care sector in 2021, so far.

All affected patients will receive free credit monitoring and identity theft protection. DMG has since implemented further cybersecurity measures. The organization is in the process of reviewing security policies to prevent a recurrence and improve its “technology roadmap.” Local law enforcement is continuing to investigate the incident.

Sources

Sources available to members: 1 source.

CSIDB