CSIDB logo
Incident

Harper County Community Hospital

Incident posture

Attack window
Mar 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
Harper County Community Hospital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Harper County Community Hospital experienced a ransomware attack compromising protected health information, including patient names, dates of birth, addresses, account numbers, diagnoses, Social Security numbers, and health insurance details. The breach exposed sensitive data, prompting disclosure by the hospital, though it had not yet been listed on official regulatory breach reports at the time of reporting.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 24, 2021, Harper County Community Hospital in Oklahoma experienced a ransomware attack that compromised protected health information. The hospital publicly disclosed the incident through a notice on its website, though federal authorities had not yet listed it on the U.S. Department of Health and Human Services' breach reporting tool at the time of initial media coverage. Attackers gained unauthorized access to systems containing sensitive patient data, including first and last names, dates of birth, home addresses, patient account numbers, medical diagnoses, Social Security numbers, and health insurance information. The hospital did not specify the ransomware variant used or the exact number of affected individuals in its initial disclosure. No operational disruptions or ransom demands were mentioned in available reports.

The hospital initiated breach notification procedures following the attack, alerting patients about potential exposure of their personal and medical data. Authorities investigating the incident confirmed the types of compromised information but did not disclose whether data exfiltration occurred prior to encryption. The incident remained under active investigation with no public details regarding containment measures, system restoration processes, or potential data misuse. Based on standard reporting timelines, industry observers anticipated the breach would eventually appear in official HHS records once regulatory notifications were completed. The compromised data elements created significant identity theft and medical fraud risks for affected patients due to the inclusion of Social Security numbers and clinical diagnosis information.

Sources

Sources available to members: 1 source.

CSIDB