Menu
Browse

Cyber Incident Victim: Robeson Health Care Corporation

Date:

Feb 2023

Location:

United States of America

Summary

A healthcare provider experienced a malware attack that resulted in unauthorized system access over several days, compromising sensitive patient information. The breach exposed personal and medical details including names, addresses, Social Security numbers, dates of birth, diagnoses, physician details, insurance data, prescription information, and treatment costs. Following malware detection, the organization disconnected its network and engaged forensic specialists to investigate the incident. After confirming data exposure affecting over 15,000 individuals, notification letters were distributed to impacted parties. The provider operates multiple health centers across four counties, offering physical and mental health services while employing hundreds of staff with substantial annual revenue.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 4 motives 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On February 21, 2023, Robeson Health Care Corporation (RHCC) discovered malware on its computer systems, prompting an immediate disconnection of its network from the internet. The healthcare provider engaged third-party forensic specialists to investigate the scope and origin of the compromise. The investigation confirmed unauthorized access to RHCC's systems between February 17, 2023, and February 23, 2023. By March 31, 2023, forensic analysis determined that files accessible during this intrusion contained sensitive patient information. A subsequent file review identified compromised data including names, addresses, Social Security numbers, dates of birth, treatment details, diagnoses, physician information, medical record numbers, patient ID numbers, Medicare/Medicaid identifiers, prescription history, health insurance details, and treatment cost data. The breach impacted over 15,000 individuals based on RHCC's filing with the Maine Attorney General’s office.

Cyber Incident Image

RHCC initiated data breach notifications to affected patients on April 21, 2023, concurrently submitting its formal notice to Maine regulators. The malware attack exposed protected health information alongside personally identifiable information, elevating risks of medical identity theft and financial fraud for impacted individuals. As a North Carolina-based provider operating seven health centers across four counties, RHCC serves patients requiring physical and mental health services. The organization employs 234 staff and generates $32 million in annual revenue. No ransomware deployment or explicit data theft claims were disclosed in the breach notice. Forensic investigations concluded the unauthorized party’s access window without detailing persistent threats or data exfiltration methods. Patient notification letters specified the types of compromised data but did not provide individual-level breach confirmation timelines or data recovery assurances.

Sources
Sources available to members
1 source