Cyber Incident Victim: Lubbock Cardiology Clinic
Date:
Dec 2013
Location:
United States of America
Summary
Unauthorized access to Lubbock Cardiology Clinic's electronic health record system compromised over 1,400 medical records containing sensitive personal information including names, contact details, and Social Security numbers. The breach prompted an ongoing investigation and public notification directing potentially affected individuals to contact a dedicated phone number for further information while efforts to recover the data continued.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Between December 15, 2013, and January 30, 2014, unauthorized individuals gained access to the Electronic Health Record (EHR) system utilized by Lubbock Cardiology Clinic (LCC), a Texas-based medical provider. This intrusion compromised the protected health information of more than 1,400 patients. The breached records contained sensitive personal identifiers, including full names, residential addresses, telephone numbers, and Social Security numbers. The attackers maintained persistent access to the EHR for approximately six weeks, though the specific methods of infiltration or exploitation were not publicly disclosed in available reports. The clinic discovered the breach following an unspecified detection process, prompting immediate internal review. The compromised data posed significant risks of identity theft, financial fraud, and medical privacy violations due to the inclusion of highly sensitive Social Security numbers alongside detailed patient demographics.

Lubbock Cardiology Clinic initiated an investigation upon identifying the breach, though the scope and findings of this inquiry remained undisclosed as of April 2014. The organization posted an official notification on its digital platforms to inform potential victims, directing concerned individuals to contact a dedicated telephone line for confirmation of their involvement in the incident. Public statements emphasized active efforts to recover the compromised information, with a clinic representative asserting, “We are vigorously seeking answers and recovery of this information, and I am confident that we will be successful.” No evidence suggested ransomware deployment, data encryption, or destruction of records during the intrusion. The breach exposed systemic vulnerabilities in the clinic’s electronic record-keeping infrastructure but yielded no confirmed reports of fraudulent misuse of patient data at the time of public disclosure.
