CSIDB logo
Incident

SCL Health

Incident posture

Attack window
Feb 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-01 00:00

Linked entities

Victim
SCL Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity incident impacted a healthcare organization through a third-party service provider breach, exposing patient information at facilities in Montana including three hospitals. The unauthorized access occurred over several months, compromising names, dates of birth, contact details, admission dates, treatment locations, and provider information. Encrypted data such as Social Security numbers remained secure. Affected individuals were notified via mail and provided a dedicated contact number for assistance. The breach originated from compromised systems at the external vendor responsible for managing patient data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

SCL Health Medical Group publicly disclosed a data breach impacting patient information on September 10, 2020. The incident originated from a cybersecurity compromise at one of SCL Health’s third-party service providers, Blackbaud Inc., which notified the healthcare organization on July 16, 2020. Blackbaud reported that an unauthorized individual gained access to its systems containing SCL Health patient data during a period spanning February 7 to May 20, 2020. This breach affected patients treated at three Montana hospitals operated by SCL Health: St. Vincent Healthcare in Billings, St. James Healthcare in Butte, and Holy Rosary Healthcare in Miles City. The exposed information included patient names, dates of birth, physical addresses, phone numbers, email addresses, admission dates, hospital locations, specific service locations within facilities, and names of treatment providers. Blackbaud confirmed that encrypted fields containing more sensitive data such as Social Security numbers were not accessed during the intrusion.

SCL Health initiated breach notification procedures approximately eight weeks after receiving Blackbaud’s disclosure, mailing individual letters to all affected patients. The organization established a dedicated call center (866-968-0158) to address patient inquiries regarding the incident. While emphasizing that financial data and Social Security numbers remained protected through encryption, SCL Health advised impacted individuals to remain vigilant in monitoring their personal information. The breach notification did not specify the total number of affected patients across the Montana facilities or describe any operational disruptions to clinical care resulting from the incident. No evidence suggested misuse of the exposed data at the time of disclosure.

Sources

Sources available to members: 1 source.

CSIDB