CSIDB logo
Incident

National Research Corporation

Incident posture

Attack window
Feb 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-01 00:00

Linked entities

Victim
National Research Corporation
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A healthcare analytics provider experienced a ransomware attack, prompting an immediate system shutdown to contain the infection. The organization confirmed no compromise of patient data, protected health information, or other confidential material during the incident. Internal teams made significant progress restoring systems with full recovery anticipated shortly, while the FBI was notified of the event. The ransomware variant involved remained unidentified, and the company declined to disclose whether any ransom payment occurred.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 11, 2020, NRC Health, a Lincoln-based healthcare analytics provider, experienced a ransomware attack that disrupted its operations. The company promptly shut down its systems to contain the infection upon detection. NRC Health specializes in delivering data-driven insights to healthcare providers to improve service quality, but the attack forced an immediate cessation of normal business activities. Internal staff initiated containment protocols to prevent lateral movement of the ransomware within the network. No evidence emerged during the initial response indicating unauthorized access to or exfiltration of protected health information, confidential data, or patient records. The company maintained operational silence regarding technical specifics of the attack vector, initial access method, or ransomware variant involved.

Paul Cooper, NRC Health’s Chief Information Officer, confirmed significant progress in system restoration within two weeks of the incident, anticipating full recovery within days of his February 25 statement. The restoration effort relied entirely on internal resources without external confirmation of third-party forensic assistance. NRC Health formally reported the incident to the FBI but did not disclose whether the bureau provided investigative support. Cooper explicitly declined to state whether the company paid a ransom to attackers. Operational impacts included temporary loss of analytics services to healthcare clients, though the duration of outages for specific systems remained unspecified. The company reiterated throughout its communications that no data compromise occurred despite the systemic disruption caused by the ransomware encryption event.

Sources

Sources available to members: 1 source.

CSIDB