CSIDB logo
Incident

Roper St. Francis Healthcare

Incident posture

Attack window
Feb 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-07-15 02:03

Linked entities

Victim
Roper St. Francis Healthcare
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A healthcare provider experienced a data security breach affecting nearly 93,000 patients through a third-party vendor's compromised fundraising database. An unauthorized party potentially accessed personal information including names, ages, genders, birthdates, addresses, treatment dates, service departments, and treating physicians, though encrypted financial data and Social Security numbers remained protected. The incident was confined to fundraising systems without impacting medical records or clinical operations. The organization notified affected individuals, established a dedicated call center for inquiries, and initiated reviews of third-party data storage practices while reassessing its vendor relationship following the breach.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Roper St. Francis Healthcare (RSFH) experienced a data security breach involving its third-party vendor Blackbaud, which managed fundraising information for the healthcare system. Blackbaud notified RSFH on July 31, 2020, that an unauthorized party had accessed its systems between February 7 and May 20, 2020. The attackers potentially acquired a backup copy of the fundraising database maintained by Roper St. Francis Foundations. This incident affected approximately 93,000 patients whose information was stored in the compromised database. The breached data included patients' names, ages, genders, dates of birth, addresses, dates of treatment, departments of service, and treating physicians. Blackbaud confirmed that encrypted fields containing Social Security numbers, financial account details, and credit card information remained inaccessible to the attackers. RSFH emphasized that medical systems and electronic health records were not involved in the breach, limiting exposure to fundraising-related data.

Following notification from Blackbaud, RSFH initiated a patient notification process and established a dedicated call center operational Monday through Friday to address inquiries. The healthcare provider advised affected individuals to review statements from their healthcare providers for discrepancies and report unrecognized services immediately. Internally, RSFH launched a review of its data storage practices with third-party vendors and began re-evaluating its business relationship with Blackbaud. The breach did not disrupt clinical operations or compromise medical treatment systems, but it exposed non-medical patient information that could be exploited for identity theft or phishing attempts. No evidence suggested misuse of the accessed data at the time of disclosure, though the incident highlighted risks associated with third-party vendor management in healthcare data ecosystems.

Sources

Sources available to members: 1 source.

CSIDB