Menu
Browse

Cyber Incident Victim: Brandywine Urology

Date:

Jan 2020

Location:

United States of America

Summary

A ransomware attack compromised a healthcare provider's network, potentially exposing data of over 131,000 patients. The automated intrusion aimed to encrypt systems for financial gain rather than data theft, though accessed information may have included names, contact details, Social Security numbers, medical records, and financial data. The organization contained the incident by isolating affected servers, replacing compromised infrastructure, and deploying enhanced antivirus protections while collaborating with external security experts to investigate and strengthen defenses. Electronic medical records remained unaffected during the event.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On January 25, 2020, a ransomware attack began targeting the network systems of Brandywine Urology Consultants, a Delaware-based medical practice. The intrusion was discovered two days later on January 27 when staff identified active ransomware encryption processes. Practice officials immediately isolated the compromised systems to contain the attack and initiated mitigation procedures to halt further network intrusion. Forensic analysis indicated the attack was confined to Brandywine's internal network infrastructure and did not penetrate the separate electronic medical records system. The ransomware operated as an automated encryption event designed to lock data and extort payment rather than a targeted data exfiltration effort. Security scans conducted after neutralizing the threat confirmed malware removal from the central server but could not definitively rule out potential patient data access during the encryption process.

Cyber Incident Image

Brandywine engaged a third-party cybersecurity firm to investigate the incident's scope, which remains ongoing as of the April 2020 disclosure. The practice determined that 131,825 patients had personal information exposed to potential compromise, including names, contact details, Social Security numbers, medical file identifiers, insurance claims data, and financial records. In response, Brandywine replaced its central server entirely and permanently isolated all affected servers. All compromised workstations were either replaced or wiped and reloaded with clean operating systems. The practice deployed updated antivirus software across its infrastructure and initiated comprehensive security testing with its external consultants. These measures aimed to strengthen system integrity while continuing to evaluate additional security enhancements to prevent recurrence. Impacted patients received breach notifications detailing the exposed data categories but no evidence suggested actual misuse of information at the time of disclosure.

Sources
Sources available to members
1 source