CSIDB logo
Incident

Klickitat Valley Health

Incident posture

Attack window
Feb 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 11:51

Linked entities

Victim
Klickitat Valley Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Klickitat Valley Health experienced an IT security incident after an unauthorized person obtained copies of certain files from its systems, prompting containment efforts, an investigation with external cybersecurity experts, and notification to law enforcement. The compromised data varied by individual and included names, addresses, dates of birth, Social Security numbers, health insurance details, medical record numbers, patient account numbers, and treatment-related information such as dates of service, physician names, departments, and diagnoses. No financial account or payment card information was involved. The organization is mailing notification letters to affected patients, offering complimentary credit monitoring and identity protection services to those whose Social Security numbers were exposed, and has established a toll-free call center to address inquiries.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 18, 2025, an unauthorized person obtained copies of certain files from the IT systems of Klickitat Valley Health (KVH), a healthcare provider. The intrusion was not immediately detected at the moment of file access, and five days elapsed before KVH identified unusual activity affecting its IT systems on February 23, 2025. Once that anomalous activity was observed, KVH responded by taking immediate steps to contain the incident. An investigation was launched with the assistance of external cybersecurity experts, and the incident was reported to law enforcement. Through the subsequent investigation, KVH confirmed that the earlier, unauthorized access on February 18 had resulted in the removal of copies of files from its environment.

The data involved in the incident varied by individual but included a range of personally identifiable and protected health information. The information accessed and copied included names, addresses, dates of birth, Social Security numbers, health insurance information, medical record numbers, and patient account numbers. In addition, some information related to care received at KVH was included, such as dates of service, physician names and departments, and diagnosis or other treatment information. KVH noted that there was no financial account and/or payment card information involved in this incident. The combination of identifiers, clinical details, and insurance data indicates that the exposed records held enough information to identify affected patients and tie that identification to the care they received at KVH.

In response to the incident, KVH undertook containment and investigative actions, engaged external cybersecurity specialists, and notified law enforcement. The organization stated that it is continually enhancing the security of its electronic systems and the patient data it maintains in order to help prevent similar events from occurring in the future. KVH also began mailing letters to the affected patients and set up a dedicated communication channel to support them. For individuals whose Social Security numbers were involved, KVH is offering complimentary credit monitoring and identity theft protection services. Patients were encouraged to review statements received from their healthcare providers and health insurers and to immediately report any inaccuracies to the provider or insurer. A toll-free call center was established for questions about the incident; it can be reached at 1-855-374-7069, Monday through Friday, between 6:00 a.m. and 6:00 p.m. Pacific Time. KVH expressed regret for any concern the incident may cause and reiterated its commitment to the security of its systems and to continuing to provide care to its patients.

Sources

Sources available to members: 1 source.

CSIDB