Menu
Browse

Cyber Incident Victim: Seeley Medical

Date:

Aug 2020

Location:

United States of America

Summary

A ransomware attack compromised Seeley Medical, an Ohio-based home medical equipment provider, resulting in unauthorized access to sensitive patient data. The breach occurred over several days in late August to early September when malware blocked system access and allowed exfiltration of files containing names, addresses, phone numbers, medical record numbers, Social Security numbers, and prescription details affecting 16,196 individuals. The company initiated an investigation upon detection, offered affected parties credit monitoring services, and began reviewing its data security protocols. While the specific malware variant remained unconfirmed, the incident reflected broader targeting of healthcare entities during this period.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On September 7, 2020, Seeley Enterprises Company, operating as Seeley Medical in Ohio, detected suspicious activity on its network. The home medical equipment provider promptly initiated an investigation, which confirmed that malware had infected its systems, preventing access to certain files. Forensic analysis determined that an unauthorized actor had infiltrated the network between August 31 and September 7, 2020, introducing malware while accessing and acquiring specific files. The compromised data included patient names, addresses, phone numbers, medical record numbers, Social Security numbers, and prescription information. Seeley Medical reported the breach to the U.S. Department of Health and Human Services on November 6, 2020, disclosing that 16,196 patients were affected. The company engaged external legal counsel to manage breach notifications and response efforts.

Cyber Incident Image

Seeley Medical offered affected individuals 12 months of complimentary credit monitoring services following the incident. The organization also committed to reviewing its policies, procedures, and processes related to personal information storage and access controls. Neither Seeley Medical nor its external counsel responded to inquiries about the specific malware variant involved or whether the company received or paid any ransom demands prior to the article’s publication date of November 19, 2020. The breach timeline indicates a one-week period of unauthorized access before detection, with no public confirmation of data recovery or system restoration outcomes. The incident exposed sensitive patient identifiers and medical details, creating potential risks of identity theft and medical fraud for impacted individuals.

Sources
Sources available to members
1 source