Menu
Browse

Cyber Incident Victim: Horizon House

Date:

Mar 2021

Location:

United States of America

Summary

A ransomware attack compromised a Philadelphia-based mental healthcare provider's IT systems, leading to unauthorized access and data exfiltration affecting over 27,000 individuals. The breach exposed sensitive personal and medical information including names, Social Security numbers, financial account details, medical diagnoses, treatment records, and health insurance data. The organization detected suspicious network activity, initiated an investigation confirming the ransomware infection and data theft, and subsequently notified impacted individuals while advising vigilance against potential fraudulent activities.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 5, 2021, Horizon House, Inc., a Philadelphia-based mental health and residential treatment services provider, detected suspicious activity on its IT network. An investigation determined that unauthorized actors had accessed Horizon House systems between March 2 and March 5, 2021, during which time they deployed ransomware and exfiltrated sensitive data. The cyberattack compromised personal and medical information belonging to 27,823 individuals. Forensic analysis revealed the attackers obtained names, addresses, Social Security numbers, driver's license numbers, state identification card numbers, dates of birth, financial account information, medical claim details, medical record numbers, patient account numbers, medical diagnoses, treatment information, and health insurance data. Horizon House publicly disclosed the breach through a security notice but did not specify whether ransom demands were made or paid.

Cyber Incident Image

The organization completed a review of compromised files and began notifying all affected individuals following the investigation. Impacted parties received guidance to monitor for fraudulent activity stemming from the exposure of their sensitive information. No additional technical containment measures or system restoration details were publicly documented beyond the detection timeline. The incident exposed highly sensitive psychotherapy-related data alongside traditional identifiers and financial records, significantly elevating privacy risks for victims. Horizon House did not report operational disruptions to clinical services but confirmed the breach involved both data theft and encryption via ransomware. Regulatory notifications were made in compliance with healthcare data breach requirements, though specific agencies were not named in the disclosure.

Sources
Sources available to members
1 source