Menu
Browse

Cyber Incident Victim: Wedge Recovery Centers

Date:

Jun 2021

Location:

United States of America

Summary

A Philadelphia-based mental health service provider experienced unauthorized access to its computer network, prompting immediate containment measures and an investigation. The breach compromised sensitive patient information including names, addresses, Social Security numbers, dates of birth, treatment details, and health insurance data, though no evidence indicated actual misuse of the information. Approximately 29,000 individuals were affected, with the organization enhancing technical safeguards and revising policies to strengthen security. Notifications were sent to impacted patients advising vigilance against identity theft, while the incident was reported to federal health authorities.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On June 25, 2021, Wedge Recovery Centers, a Philadelphia-based mental health service provider, detected suspicious activity within its computer network indicating unauthorized access. The organization immediately blocked further intrusion attempts and initiated an investigation to determine the breach's scope and impact. Forensic analysis confirmed an unauthorized actor had infiltrated the network on the same day of detection, though investigators found no evidence suggesting any compromised information was actually or attemptedly misused. A comprehensive review of potentially affected data revealed that exposed files contained patient names, addresses, dates of birth, Social Security numbers, treatment details, and health insurance information. This review remained ongoing at the time of public disclosure. The breach ultimately impacted 29,000 individuals, as subsequently reported to the Department of Health and Human Services' Office for Civil Rights.

Cyber Incident Image

In response to the incident, Wedge Recovery Centers implemented additional technical security safeguards designed to prevent similar breaches. The organization also initiated reviews and enhancements of existing policies and procedures to strengthen privacy and security measures. Affected individuals received mailed notifications advising vigilance against identity theft and fraud, with specific recommendations to monitor account statements, explanation of benefits documents, and credit reports for suspicious activity. The provider did not publicly disclose whether law enforcement was engaged or whether third-party cybersecurity firms assisted in the investigation. No ransomware deployment, data exfiltration evidence, or financial motives were mentioned in the disclosure. The breach notification emphasized containment of the incident to the June 25 intrusion date without indicating prior or subsequent unauthorized access periods.

Sources
Sources available to members
1 source