Cyber Incident Victim: VPN Solutions
Date:
Oct 2021
Location:
United States of America
Summary
A cyberattack targeting VPN Solutions, a business associate managing electronic medical records for Arlington Skin via the Allscripts platform, potentially compromised sensitive patient information including names, addresses, dates of birth, diagnostic and treatment details, health insurance data, and Social Security numbers. The breach was discovered by the vendor, prompting a forensic investigation that found no evidence of data theft; however, notifications were sent to over 17,000 affected individuals, who were offered complimentary fraud assistance and remediation services as a precautionary measure.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around October 31, 2021, Virtual Private Network Solutions (VPN Solutions) discovered a cyberattack affecting systems it managed for Arlington Skin, a medical practice operated by Dr. Michelle A. Rivera in Virginia. VPN Solutions served as a business associate responsible for managing Arlington Skin's electronic medical records through the Allscripts practice management solution and electronic medical records platform. Following the detection of unauthorized access, VPN Solutions initiated a forensic investigation to determine the nature and scope of the security incident. The investigation confirmed that unauthorized individuals potentially accessed protected health information of Arlington Skin patients during the breach window. The compromised data categories included patient names, addresses, dates of birth, diagnostic and treatment information, health insurance details, and Social Security numbers. No forensic evidence confirmed actual data exfiltration or theft from the systems.

The forensic review concluded that 17,468 Arlington Skin patients had their information exposed in the incident. Notification letters detailing the breach were mailed to affected individuals beginning July 8, 2022—approximately eight months after the attack's discovery. Although investigators found no proof that attacker accessed or misused patient data, VPN Solutions and Arlington Skin provided complimentary fraud assistance and identity remediation services through CyberScout as a precautionary measure. The breach notification process occurred separately from a larger unrelated incident involving First Choice Community Healthcare, which VPN Solutions was not associated with. Arlington Skin's breach disclosure occurred through substitute notices coordinated with federal reporting requirements, with no additional operational disruptions or secondary attacks reported in the source material.
