Menu
Browse

Cyber Incident Victim: Christiana Spine Center

Date:

Feb 2022

Location:

United States of America

Summary

Christiana Spine Center experienced a ransomware attack detected during containment efforts, prompting an investigation with forensic experts. The breach potentially exposed patient names, addresses, phone numbers, Social Security numbers, health insurance identifiers, and personal health information, affecting approximately 3,500 individuals. Complimentary credit monitoring was provided to those impacted, though no evidence confirmed data theft or misuse occurred.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On February 25, 2022, Christiana Spine Center in Newark, Delaware, detected a ransomware attack on its systems. The organization immediately implemented containment measures to halt further unauthorized access and mitigate potential damage. Forensic and cybersecurity experts were engaged to investigate the nature and scope of the breach. The investigation confirmed that unauthorized actors had gained access to files containing sensitive patient information. While the attackers deployed ransomware to encrypt files, the forensic review focused on determining whether data exfiltration occurred. The analysis revealed that accessed files included patient names, addresses, phone numbers, Social Security numbers, health insurance identification numbers, and personal health information. No evidence confirmed the theft or misuse of patient data despite the confirmed system access.

Cyber Incident Image

The review process identified approximately 3,500 patients whose protected information resided in the compromised files. Christiana Spine Center notified these individuals about the potential exposure of their data following the completion of the forensic investigation. As a remedial measure, the organization offered affected patients complimentary 12-month memberships to a credit monitoring service. The incident did not result in public data leaks or ransom demands attributed to the attack based on available evidence. Operational recovery efforts proceeded alongside the investigation, though specific technical details about system restoration were not disclosed. Christiana Spine Center maintained that no subsequent misuse of patient information had been detected following the containment of the February 2022 incident.

Sources
Sources available to members
1 source