CSIDB logo
Incident

Valley View Hospital

Incident posture

Attack window
Jan 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-21 19:09

Linked entities

Victim
Valley View Hospital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A computer virus compromised sensitive information of approximately 5,400 patients at Valley View Hospital, capturing screenshots of personal data including names, addresses, Social Security numbers, payment card details, dates of birth, phone numbers, admission and discharge dates, and patient visit numbers. The virus stored this information in an encrypted hidden folder on the hospital network, with potential unauthorized external access remaining unconfirmed. Upon discovery, the institution shut down network traffic, eliminated the malware, engaged forensic investigators to analyze the incident, and implemented security upgrades alongside expanded IT protocols. All affected individuals were notified as part of the response efforts.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In January 2014, Valley View Hospital in Colorado identified a computer virus on hospital systems that compromised sensitive personal information of approximately 5,400 patients. The virus, discovered on January 23, captured screenshots containing patient data and stored them within an encrypted and hidden folder on the hospital’s network. Exposed information included names, addresses, dates of birth, phone numbers, Social Security numbers, payment card details, admission and discharge dates, and patient visit numbers. Forensic analysis confirmed the virus’s operation by January 25 but could not verify whether unauthorized external parties accessed or transmitted the stored data. The hospital acknowledged the possibility of external access to the encrypted folder, heightening concerns about potential misuse of the highly sensitive financial and identification records.

Upon detecting the virus, Valley View Hospital immediately shut down all incoming and outgoing network traffic to contain the threat and initiated measures to eliminate the malware. The hospital engaged a forensic team to analyze the virus’s behavior and impact, leading to subsequent upgrades in its information security program and expanded IT security procedures. All affected individuals received direct notifications about the breach, with the hospital publicly disclosing the incident in March 2014 through its website. CEO Gary Brewer emphasized the hospital’s rapid and comprehensive response, including ongoing monitoring and support for potentially impacted patients. The institution maintained transparency about its inability to confirm data exfiltration while reinforcing its commitment to security enhancements following the incident.

Sources

Sources available to members: 1 source.

CSIDB