CSIDB logo
Incident

Proton Therapy Center

Incident posture

Attack window
Oct 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-28 00:00

Linked entities

Victim
Proton Therapy Center
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Tennessee-based proton therapy provider experienced a cybersecurity incident affecting operations in multiple locations, leading to temporary disruptions in clinical and financial systems. The organization implemented extensive security protocols and worked with external partners to restore IT functionality while relying on offline backup processes to maintain continuity. Although the breach caused operational challenges, patient care delivery remained unaffected and there was no evidence of unauthorized access or misuse of patient or employee data during the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On October 28, 2020, Proton Therapy Center, LLC (PCPT) in Knoxville and MTPC, LLC (MTPC) in Nashville experienced an information technology security incident during early morning hours. Both facilities, which provide cancer treatment through proton radiation therapy and were financed through municipal bonds, immediately initiated response protocols following the breach. The incident caused operational disruptions affecting clinical and financial systems, though the centers maintained patient care delivery through established contingency measures. By December 2, 2020, the organizations disclosed these disruptions in a bond filing, characterizing them as temporary but ongoing. Neither entity specified the attack vector or duration of system compromise in public reports.

The centers implemented extensive IT security protocols and collaborated with external security partners to restore operations, prioritizing system recovery while maintaining offline documentation methods as temporary workarounds. Clinical operations continued without interruption to patient treatments, with no evidence suggesting compromised safety standards during the incident response period. Financial operations experienced more significant disruptions, though the filing did not detail specific impacted processes. Investigations found no evidence that patient or employee data was accessed, copied, or misused. Both facilities maintained their backup processes throughout the recovery period, which extended beyond the initial disclosure date. The bond filing served as the primary public notification mechanism regarding the incident's operational impacts.

Sources

Sources available to members: 1 source.

CSIDB