Cyber Incident Victim: CareATC
Timeline
Summary
DuPage Medical Group disclosed that a cyberattack and ensuing network outage exposed personal information of approximately 655,000 patients after threat actors gained access to parts of its network during the incident. A forensic investigation found that the compromised data could include names, contact details, diagnosis codes, procedure codes, treatment dates, and Social Security numbers for a subset of individuals, while no financial information was affected. All affected patients were offered free credit monitoring and identity theft protection, and the organization has since strengthened its security controls, reviewed policies, and is working with law enforcement on the ongoing investigation.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 13, 2021, DuPage Medical Group reported a security incident that disrupted its network systems. Investigation revealed that threat actors gained access to the network between July 12 and July 13. Upon discovery, DMG launched an investigation into the impact alongside a third‑party cyber‑forensic specialist firm. The forensic team conducted a review to assess whether patient information was affected. The review confirmed that the hackers had access to just certain portions of the network and the patient data stored on those systems.

The compromised data could include names, contact details, diagnosis codes, Current Procedural Terminology (CPT) codes tied to procedures, and treatment dates. Along with those elements, Social Security numbers for a subset of patients were also potentially exposed. No financial information was impacted by the breach. DuPage Medical Group began notifying 655,384 patients that their data was compromised during the cyberattack and network outage in mid‑July. With its breach tally, the DMG hack is among the ten largest incidents reported in the health care sector in 2021, so far.
All affected patients will receive free credit monitoring and identity theft protection. DMG has since implemented further cybersecurity measures. The organization is in the process of reviewing security policies to prevent a recurrence and improve its “technology roadmap.” Local law enforcement is continuing to investigate the incident.
