CSIDB logo
Incident

Proliance Surgeons, Inc.

Incident posture

Attack window
Nov 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-09 19:23

Linked entities

Victim
Proliance Surgeons, Inc.
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A surgical practice experienced a data security incident affecting its corporate website, potentially exposing payment card information for customers who used the online payment platform. The compromised data included cardholder names, account numbers, expiration dates, and zip codes, but exclusively impacted online payments—not in-person or phone transactions. No patient healthcare records or other sensitive personal information were accessed. The organization contained the incident, engaged forensic experts to identify the source, and implemented enhanced security measures through a new website and payment platform. Coordination with payment card networks occurred to mitigate fraudulent activity risks.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Proliance Surgeons, Inc. detected a data security incident involving its corporate website, prompting immediate containment efforts and the initiation of an internal investigation. The organization engaged a digital forensics firm to assist in determining the nature and scope of the breach. The investigation revealed that unauthorized access potentially exposed payment card information for customers who used Proliance’s online payment platform between November 13, 2019, and June 24, 2020. The compromised data included cardholder names, payment card account numbers, expiration dates, and zip codes associated with online transactions. No evidence indicated that in-person or telephone payments were affected. The incident exclusively impacted the online payment system, with no exposure of patient healthcare records, protected health information, or other categories of sensitive personal data beyond the specified payment details.

Following the investigation, Proliance coordinated with major payment card brands to implement fraud prevention measures for potentially compromised accounts. The digital forensics team helped identify the incident’s source, enabling Proliance to secure the compromised payment platform. The organization subsequently launched a redesigned website and payment system incorporating enhanced security protocols to reduce future risks. Proliance notified affected customers, advising them to review payment card statements for unauthorized activity and contact their financial institutions if discrepancies were detected. The surgical practice maintained operations across its Washington State care centers throughout the incident response, emphasizing that clinical systems and patient treatment workflows remained unaffected.

Sources

Sources available to members: 1 source.

CSIDB