Menu
Browse

Cyber Incident Victim: Harper County Community Hospital

Date:

Mar 2021

Location:

United States of America

Summary

Harper County Community Hospital experienced a ransomware attack compromising protected health information, including patient names, dates of birth, addresses, account numbers, diagnoses, Social Security numbers, and health insurance details. The breach exposed sensitive data, prompting disclosure by the hospital, though it had not yet been listed on official regulatory breach reports at the time of reporting.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 24, 2021, Harper County Community Hospital in Oklahoma experienced a ransomware attack that compromised protected health information. The hospital publicly disclosed the incident through a notice on its website, though federal authorities had not yet listed it on the U.S. Department of Health and Human Services' breach reporting tool at the time of initial media coverage. Attackers gained unauthorized access to systems containing sensitive patient data, including first and last names, dates of birth, home addresses, patient account numbers, medical diagnoses, Social Security numbers, and health insurance information. The hospital did not specify the ransomware variant used or the exact number of affected individuals in its initial disclosure. No operational disruptions or ransom demands were mentioned in available reports.

Cyber Incident Image

The hospital initiated breach notification procedures following the attack, alerting patients about potential exposure of their personal and medical data. Authorities investigating the incident confirmed the types of compromised information but did not disclose whether data exfiltration occurred prior to encryption. The incident remained under active investigation with no public details regarding containment measures, system restoration processes, or potential data misuse. Based on standard reporting timelines, industry observers anticipated the breach would eventually appear in official HHS records once regulatory notifications were completed. The compromised data elements created significant identity theft and medical fraud risks for affected patients due to the inclusion of Social Security numbers and clinical diagnosis information.

Sources
Sources available to members
1 source