Menu
Browse

Cyber Incident Victim: Southwest Health Center

Date:

Jan 2022

Location:

United States of America

Summary

Southwest Health Center, a Wisconsin healthcare provider, experienced a data security incident involving unauthorized access to systems containing sensitive personal and protected health information. The breach potentially affected current and former employees, their dependents, and patients, exposing names, Social Security numbers, financial account details, medical records, and insurance information. The organization secured its network, initiated forensic investigations, and notified impacted individuals while offering complimentary credit monitoring and identity theft restoration services. No evidence of data misuse has been identified.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Southwest Health Center, a healthcare provider based in Platteville, Wisconsin, discovered a potential data security incident on January 11, 2022, impacting certain systems within its network. Upon identifying the incident, the organization immediately implemented measures to secure its network infrastructure and engaged external cybersecurity experts to conduct a forensic investigation. The investigation determined that unauthorized actors may have accessed or acquired sensitive personal and protected health information during the incident. Southwest Health subsequently initiated a comprehensive review of the potentially compromised data to identify affected individuals and the specific types of information involved. The forensic analysis confirmed the incident affected current and former employees, their dependents or beneficiaries, and individuals who had received medical treatment or services at the facility.

Cyber Incident Image

The compromised information included names, dates of birth, Social Security numbers, driver's license or state identification card numbers, financial account numbers, medical records, and health insurance details. On July 5, 2022—nearly six months after detection—Southwest Health began notifying potentially impacted individuals via mailed letters detailing the incident and protective measures available to them. The organization offered complimentary credit monitoring and identity theft restoration services to affected parties. Southwest Health established a dedicated toll-free call center operational Monday through Friday from 8:00 AM to 8:00 PM Central Time to address inquiries, with additional resources provided through a dedicated response website. While no actual misuse of the compromised information had been identified at the time of notification, the organization emphasized the privacy and protection of personal data as its top priority in public statements regarding the breach.

Sources
Sources available to members
1 source