CSIDB logo
Incident

Putnam County Memorial Hospital

Incident posture

Attack window
Jul 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-24 00:00

Linked entities

Victim
Putnam County Memorial Hospital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Putnam County Memorial Hospital experienced a cyberattack that disrupted system and file access, leading to unauthorized network intrusion involving reconnaissance tools and ransomware deployment. The attacker potentially accessed patient and employee data including names, addresses, Social Security numbers, medical assessments, authorizations, and lab reports, though financial information remained uncompromised. Approximately 6,916 individuals were affected, prompting the implementation of enhanced security measures and complimentary credit monitoring services featuring darknet surveillance, identity theft restoration support, and insurance coverage.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Putnam County Memorial Hospital in Unionville, Missouri, experienced a cyberattack detected on July 18, 2021, when staff were prevented from accessing certain computer systems and files. Forensic investigations determined an unauthorized actor had infiltrated the hospital’s network between July 16 and July 18, 2021. During this period, the attacker deployed multiple network reconnaissance tools to identify systems and data of interest before encrypting files with ransomware. The compromised sections of the network contained sensitive patient and employee information, including names, addresses, Social Security numbers, physician-patient assessments, medical records, treatment authorizations, and laboratory and radiology reports. Financial data was not confirmed to have been exposed in the breach. The attack disrupted hospital operations by restricting access to critical systems necessary for daily functions.

Following containment efforts, the hospital initiated a forensic review to assess the scope of the incident. The investigation confirmed the attacker’s access to protected health information but found no evidence of financial data compromise. In response, Putnam County Memorial Hospital implemented new security measures to enhance data protection protocols. Notifications were issued to 6,916 affected individuals, detailing the types of exposed information and offering complimentary 12-month credit monitoring services. These services included darknet and clearnet monitoring, quick cash scans, fraud consultation, identity theft restoration support, and identity theft insurance coverage. The hospital’s remediation efforts focused on restoring system integrity and preventing future unauthorized access through strengthened cybersecurity controls.

Sources

Sources available to members: 1 source.

CSIDB