CSIDB logo
Incident

Hospice of San Joaquin

Incident posture

Attack window
Jul 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-03 00:00

Linked entities

Victim
Hospice of San Joaquin
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Hospice of San Joaquin experienced a ransomware attack compromising servers containing sensitive patient information, including full names, identification numbers, medical diagnoses, and home addresses. Although the attackers accessed the data, the organization found no evidence of misuse or unauthorized disclosure, and confirmed donor and vendor records were unaffected by the breach.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 2, 2019, Hospice of San Joaquin experienced a ransomware attack compromising its servers. The organization notified the California Attorney General’s Office about the breach, with CEO Rebecca Burnett signing the disclosure. Malicious software accessed servers containing sensitive patient information, including full names, patient ID numbers, diagnoses, and home addresses. The hospice explicitly stated donor and vendor data remained unaffected by the incident. While confirming unauthorized access to protected health information (PHI), the organization asserted no evidence indicated misuse, dissemination, or disclosure of the compromised data to unauthorized third parties. The public disclosure occurred on August 21, 2019, through a breach notice lacking technical specifics about the ransomware variant or initial attack vector.

Hospice of San Joaquin did not disclose whether it paid ransom demands or detailed its data restoration process. The notification omitted critical details including the number of affected patients, whether families’ personal information was exposed beyond patient PHI, and the operational impact on hospice services. No information was provided regarding containment measures, forensic investigations, or system recovery timelines. The organization’s communication focused exclusively on confirming the breach’s occurrence and the categories of potentially exposed data while emphasizing their belief in the integrity of the compromised information despite the encryption event. Public reporting highlighted significant unresolved questions about the attack’s scope and the hospice’s incident response actions beyond mandatory regulatory notification.

Sources

Sources available to members: 1 source.

CSIDB