CSIDB logo
Incident

Southeastern Minnesota Oral & Maxillofacial Surgery

Incident posture

Attack window
Sep 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-07 00:00

Linked entities

Victim
Southeastern Minnesota Oral & Maxillofacial Surgery
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Minnesota healthcare facility specializing in oral and maxillofacial treatments experienced a ransomware attack affecting a server, prompting immediate IT intervention to restore impacted data. The incident potentially exposed health information, including patient names and X-ray images, for approximately 80,000 individuals, though forensic analysis could not confirm unauthorized access or misuse. While financial data, medical records, and Social Security numbers remained unaffected, the organization notified all potentially impacted patients and initiated a review of cybersecurity policies to prevent future incidents.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 23, 2019, Southeastern Minnesota Oral & Maxillofacial Surgery (SEMOMS) experienced a ransomware attack targeting one of its servers. The organization’s IT staff responded immediately to contain the incident and successfully restored the impacted data from backups. SEMOMS publicly disclosed the breach via a website announcement on December 5, 2019, confirming the attack compromised patient health information but did not specify whether a ransom was demanded or paid. Forensic investigators hired by SEMOMS could not conclusively determine whether attackers accessed or viewed patient names and X-ray images stored on the affected server. The organization emphasized no evidence suggested actual misuse of data or unauthorized viewing occurred during the intrusion.

The incident potentially exposed information belonging to all 80,000 patients under SEMOMS’ care, prompting mandatory notification letters that detailed the breach and provided a toll-free inquiry number. SEMOMS clarified that financial records, Social Security numbers, and full medical histories remained unaffected. In response, the organization initiated a comprehensive review of its cybersecurity policies and procedures to prevent future incidents. Remediation efforts included revising information security protocols and reinforcing data protection measures, though specific technical controls were not disclosed. SEMOMS maintained its commitment to patient privacy while acknowledging the unresolved forensic status of the compromised server’s data accessibility during the attack.

Sources

Sources available to members: 1 source.

CSIDB