Cyber Incident Victim: Extend Fertility
Date:
Dec 2021
Location:
United States of America
Summary
A ransomware attack compromised a fertility clinic's systems, potentially exposing sensitive patient data including personal details, medical histories, treatment information, and insurance data. Unauthorized actors encrypted files and likely exfiltrated information, affecting over 10,000 individuals. The organization notified patients and provided complimentary credit monitoring and identity theft protection services. Security improvements and enhanced employee training are being implemented following external consultations. No confirmed misuse of the data has been reported.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Extend Fertility, a New York City-based fertility clinic, experienced a ransomware attack initially detected on December 20, 2022. The investigation determined unauthorized actors first accessed the clinic's systems on or around December 15, 2021. Upon discovery, Extend Fertility engaged third-party computer forensics experts to analyze the breach. The attackers successfully encrypted files across the organization's network and servers during the intrusion. While data exfiltration could not be conclusively verified, forensic analysis indicated a high likelihood that files containing protected health information were extracted from the systems. The clinic completed its initial investigation on January 28, 2022, confirming the attack timeline and scope of system compromise.

The incident potentially exposed sensitive data of 10,373 patients through files that included comprehensive personal and medical details. Affected information encompassed full names, genders, home addresses, phone numbers, email addresses, dates of birth, medical histories, diagnoses, treatment details, service dates, lab test results, prescription records, provider names, medical account numbers, health insurance policy details, group plan information, and claim data. Extend Fertility found no evidence of actual or attempted misuse of the compromised information. As a precautionary measure, the clinic offered affected individuals complimentary credit monitoring and identity theft protection services. Internally, Extend Fertility initiated security improvements by collaborating with external cybersecurity consultants to implement enhanced safeguards based on their recommendations. The organization also committed to strengthening its employee cybersecurity training program to reduce future vulnerabilities.
