Menu
Browse

Cyber Incident Victim: Lincare Holdings

Date:

Apr 2017

Location:

United States of America

Summary

A ransomware attack compromised a healthcare provider's network, potentially exposing protected health information of approximately 500,000 patients. The organization, Lincare Holdings, found no evidence that data was actually accessed or acquired but issued notifications to affected individuals as a precaution. The incident was reported to relevant authorities including the U.S. Department of Health and Human Services.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On April 18, 2017, Purity Cylinder/Airway Oxygen, a Michigan-based company later identified in public records as part of Lincare Holdings, discovered ransomware had been deployed on its network. The discovery triggered an investigation to assess the nature and scope of the incident. While forensic analysis found no evidence that protected health information (PHI) was accessed, exfiltrated, or acquired by unauthorized actors, the company determined the ransomware infection created a potential risk to patient data confidentiality. The compromised systems contained sensitive information, including patient names, addresses, dates of birth, medical diagnoses, health insurance details, and Social Security numbers.

Cyber Incident Image

In early June 2017, Airway Oxygen began notifying approximately 500,000 individuals whose information was present on the affected systems during the ransomware attack. The company filed a breach report with the Vermont Attorney General’s Office, citing the incident's discovery date and the lack of confirmed data misuse. By June 22, 2017, the breach appeared on the U.S. Department of Health and Human Services (HHS) public breach portal, officially documenting the exposure of half a million records. Airway Oxygen offered affected individuals one year of complimentary credit monitoring and identity protection services as a precautionary measure. The company did not disclose the specific ransomware variant involved, initial attack vectors, or containment timelines beyond the April 18 detection date. No operational disruptions or financial demands related to the ransomware were described in public notifications.

Sources
Sources available to members
1 source