Cyber Incident Victim: Susan B. Allen Memorial Hospital
Date:
Jul 2025
Location:
United States of America
Summary
Susan B. Allen Memorial Hospital is investigating a suspected cyberattack following reports of patients being unable to schedule critical appointments due to system outages caused by anomalous network activity. A third-party cybersecurity team has been engaged to assist with recovery and investigation efforts amid a broader trend of increasing attacks targeting healthcare providers, with experts noting threat actors often focus on organizations possessing cybersecurity insurance. The hospital has committed to notifying affected individuals if personal data was compromised during the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Susan B. Allen Memorial Hospital in El Dorado, Kansas, initiated an investigation into a suspected cyberattack on July 18, 2025, following patient reports of inability to contact the facility for critical appointment scheduling. The hospital confirmed detecting anomalous network activity that resulted in a system-wide outage, disrupting normal operations. A third-party cybersecurity team was engaged to assist with forensic analysis and recovery efforts, though the hospital did not disclose the specific nature or origin of the activity. This incident occurred against a backdrop of increasing cyberattacks targeting healthcare providers nationwide, including a prior attack affecting one of Wichita's largest hospitals in 2024. Patients experienced immediate service disruptions, particularly in appointment coordination systems, though the hospital has not yet confirmed whether patient data was exfiltrated or compromised.

The hospital committed to notifying affected patients promptly if investigations revealed unauthorized access to personal information. Cybersecurity expert Bill Ramsey contextualized the attack as part of a broader trend targeting healthcare institutions perceived to have both financial resources and cybersecurity insurance policies that increase the likelihood of ransom payments. No threat actor group, attack vector, or specific compromised systems were identified in the hospital's public statements. Recovery operations remained ongoing at the time of reporting, with no estimated restoration timeline provided. The incident highlighted operational vulnerabilities in healthcare infrastructure amid escalating threats to the sector.
