Menu
Browse

Cyber Incident Victim: CareATC

Date:

Jul 2021

Location:

United States of America

Summary

A healthcare provider experienced a cyberattack causing a network outage, compromising data for over 655,000 patients. Unauthorized actors accessed portions of the network containing patient names, contact details, diagnosis and procedure codes, treatment dates, and Social Security numbers for some individuals, though no financial data was affected. The organization provided affected individuals with complimentary credit monitoring and identity theft protection while enhancing cybersecurity measures and reviewing security policies. Law enforcement continues to investigate the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 13, 2021, DuPage Medical Group (DMG) experienced a network outage caused by a cyberattack, disrupting its systems. The Illinois-based healthcare provider initiated an investigation with a third-party cyber-forensic specialist firm, which determined threat actors had gained unauthorized access to portions of the network between July 12 and July 13. Forensic analysis confirmed the attackers accessed specific segments of DMG’s infrastructure containing patient data but did not compromise all systems. The compromised information included names, contact details, diagnosis codes, Current Procedural Terminology (CPT) codes related to medical procedures, and treatment dates. Social Security numbers were exposed for a subset of affected individuals, though no financial information was involved in the breach.

Cyber Incident Image

DMG notified 655,384 patients of the incident in late August 2021, ranking it among the ten largest healthcare sector breaches reported that year. The organization offered free credit monitoring and identity theft protection services to all impacted individuals. In response to the attack, DMG implemented additional cybersecurity measures and initiated a review of its security policies and technology roadmap to prevent future incidents. Local law enforcement continued investigating the breach as of the notification date, though no specific threat actor or attack vector was publicly identified. The outage and subsequent data compromise underscored operational disruptions and risks to patient confidentiality stemming from the unauthorized network access.

Sources
Sources available to members
1 source