CSIDB logo
Incident

QRS Healthcare Solutions

Incident posture

Attack window
Aug 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-23 00:00

Linked entities

Victim
QRS Healthcare Solutions
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Aug 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A healthcare technology services company experienced a breach where an attacker compromised a patient portal and exfiltrated files containing sensitive patient information, including names, addresses, Social Security numbers, patient IDs, usernames, and medical treatment details. The intrusion was detected within three days, impacting 319,788 individuals according to regulatory filings, though a subsequent ransomware group claimed responsibility and a separate client reported an additional 6,027 affected patients. The incident was isolated to the compromised portal and did not involve other systems operated by the vendor or its clients.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On August 26, 2021, healthcare technology services provider QRS, Inc. discovered that an attacker had compromised a patient portal associated with one of its clients. The unauthorized access led to the exfiltration of files from the client’s server. QRS detected the breach within three days of the initial attack. The compromised data potentially included patients’ names, addresses, dates of birth, Social Security numbers, patient identification numbers, portal usernames, and medical treatment or diagnosis information. The company confirmed the incident was isolated to the specific client’s portal and did not affect other QRS systems or any other client environments. QRS filed a notification with the U.S. Department of Health and Human Services (HHS), reporting the breach as impacting 319,788 individuals.

On November 30, 2021, the Snatch ransomware group claimed responsibility for the attack on its dedicated leak site, though QRS did not publicly confirm this attribution. Separately, Gregory Brewer, MD PLLC—a client potentially linked to the compromised portal—reported the incident as affecting 6,027 of its patients. It remains unclear whether this figure was included in QRS’s original HHS report. No additional technical details about the attack vector, containment measures, or forensic findings were disclosed in the source material. The breach exposed sensitive protected health information but did not disrupt broader operations across QRS’s infrastructure or its other clients.

Sources

Sources available to members: 1 source.

CSIDB