Cyber Incident Victim: Wheeling Health Right
Date:
Jan 2022
Location:
United States of America
Summary
Wheeling Health Right, a West Virginia clinic providing healthcare to low-income and uninsured individuals, experienced a highly sophisticated cyberattack involving system encryption and potential unauthorized access to sensitive information. Following discovery of the incident, the organization engaged experts to investigate the breach, which compromised personal and health data including Social Security numbers, medical record numbers, tax information, driver's license details, addresses, and income-related records.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Wheeling Health Right (WHR), a West Virginia-based clinic providing healthcare services to low-income and uninsured individuals, discovered a cyberattack on January 18, 2022. The organization characterized the incident as a "highly-sophisticated cyberattack" that involved unauthorized system encryption and potential data access. WHR immediately engaged cybersecurity experts to investigate the scope and nature of the breach following detection. The forensic investigation confirmed that an unauthorized actor had successfully encrypted the clinic's systems during the attack timeframe. Analysis further revealed that the attacker potentially accessed and exfiltrated sensitive personal and health information belonging to patients and possibly other individuals associated with the clinic.

The compromised data included multiple categories of personally identifiable information and protected health information. Specifically exposed data elements encompassed full names, physical addresses, Social Security numbers, tax-related information, email addresses, telephone numbers, income details, driver's license numbers, medical record numbers, and unspecified health information. WHR initiated individual notification procedures for affected parties following completion of the investigation, though the total number of impacted individuals remained undisclosed in public reporting. The clinic's notification did not specify whether identity protection services were offered to affected individuals, unlike breach responses detailed for contemporaneous incidents at Horizon Actuarial Services and Central Indiana Orthopedics. No information regarding operational disruptions, ransom demands, or payment was disclosed in relation to the Wheeling Health Right incident.
