CSIDB logo
Incident

Lincare Holdings

Incident posture

Attack window
Apr 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-07 00:00

Linked entities

Victim
Lincare Holdings
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack compromised a healthcare provider's network, potentially exposing protected health information of approximately 500,000 patients. The organization, Lincare Holdings, found no evidence that data was actually accessed or acquired but issued notifications to affected individuals as a precaution. The incident was reported to relevant authorities including the U.S. Department of Health and Human Services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 18, 2017, Purity Cylinder/Airway Oxygen, a Michigan-based company later identified in public records as part of Lincare Holdings, discovered ransomware had been deployed on its network. The discovery triggered an investigation to assess the nature and scope of the incident. While forensic analysis found no evidence that protected health information (PHI) was accessed, exfiltrated, or acquired by unauthorized actors, the company determined the ransomware infection created a potential risk to patient data confidentiality. The compromised systems contained sensitive information, including patient names, addresses, dates of birth, medical diagnoses, health insurance details, and Social Security numbers.

In early June 2017, Airway Oxygen began notifying approximately 500,000 individuals whose information was present on the affected systems during the ransomware attack. The company filed a breach report with the Vermont Attorney General’s Office, citing the incident's discovery date and the lack of confirmed data misuse. By June 22, 2017, the breach appeared on the U.S. Department of Health and Human Services (HHS) public breach portal, officially documenting the exposure of half a million records. Airway Oxygen offered affected individuals one year of complimentary credit monitoring and identity protection services as a precautionary measure. The company did not disclose the specific ransomware variant involved, initial attack vectors, or containment timelines beyond the April 18 detection date. No operational disruptions or financial demands related to the ransomware were described in public notifications.

Sources

Sources available to members: 1 source.

CSIDB