Menu
Browse

Cyber Incident Victim: Roper St. Francis Healthcare

Date:

Jun 2020

Location:

United States of America

Summary

A data breach at Roper St. Francis Healthcare compromised approximately 6,000 patients' personal and medical information after an unauthorized actor accessed an employee's email account during a multi-day intrusion period. The stolen data included names, birth dates, Social Security numbers, insurance details, and comprehensive medical records. The healthcare provider discovered the incident after the intrusion period and established a toll-free call center for affected individuals to verify their exposure. This breach underscores the heightened value of medical data compared to financial information in illicit markets, attributed to its inclusion of extensive personally identifiable and sensitive health details.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The data breach at Roper St. Francis Hospital occurred between June 13 and June 17, 2020, when an unauthorized actor gained access to an employee’s email account. Hospital officials discovered the security incident on July 8, 2020, confirming that attackers exfiltrated sensitive information belonging to 6,000 patients. The compromised data included names, dates of birth, detailed medical records, insurance information, and Social Security numbers. Attackers specifically targeted personal and healthcare information during the five-day intrusion window. Roper St. Francis Healthcare, based in Charleston, South Carolina, publicly disclosed the breach on the same day it was discovered, confirming the attack vector as email account compromise. The hospital did not identify the responsible threat actor or disclose whether the breach involved malware, phishing, or credential theft beyond the initial email access point.

Cyber Incident Image

Affected patients were notified through a dedicated response channel established by the hospital. Starting September 4, 2020, individuals could contact a toll-free call center at 1-888-498-0916 to verify whether their data was compromised. The breach exclusively impacted a subset of patients rather than the entire healthcare system’s client base. Hospital officials confirmed the theft of comprehensive medical records alongside standard personally identifiable information but did not report evidence of data misuse in their initial disclosure. No details were provided regarding containment measures, forensic investigation methods, or system security enhancements implemented post-breach. The incident exposed vulnerabilities in email security protocols and employee account management within the healthcare provider’s infrastructure.

Sources
Sources available to members
1 source