CSIDB logo
Incident

Columbia Surgical Specialists of Spokane

Incident posture

Attack window
Jan 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-03-09 22:31

Linked entities

Victim
Columbia Surgical Specialists of Spokane
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jan 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Columbia Surgical Specialists of Spokane experienced a ransomware attack compromising protected health information of approximately 400,000 patients, including files over two decades old. The organization engaged a security firm to restore systems without paying ransom, though the breach prompted reporting to federal regulators due to potential unauthorized access to sensitive data. Patient notification complexities arose from outdated records, with the entity continuing to assess affected individuals while facing scrutiny over data retention practices and security vulnerabilities related to maintaining historical information on internet-connected servers.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 7, 2019, Columbia Surgical Specialists of Spokane experienced a ransomware attack impacting its network servers. The incident disrupted access to electronic protected health information (ePHI) stored on the practice’s systems. An information systems manager confirmed to Information Security Media Group that the organization engaged a security firm to unlock its systems and recover its data without paying a ransom. Recovery operations concluded within a few days of the initial attack. The breach affected approximately 400,000 patients, with compromised data including some patient records dating back more than 20 years. Columbia Surgical Specialists formally reported the incident to the U.S. Department of Health and Human Services (HHS) on February 18, 2019, classifying it as a network/IT server breach under HIPAA rules.

The practice acknowledged challenges in notifying affected individuals due to the age of some records, which included inactive or former patients potentially deceased or unreachable. No substitute notice or public breach notification appeared on the entity’s website despite media inquiries. DataBreaches.net documented unsuccessful attempts to obtain clarification via phone calls regarding data exfiltration risks or the rationale for retaining decades-old ePHI on internet-connected servers. Columbia Surgical Specialists did not publicly confirm whether the incident met HIPAA’s reportable breach criteria or disclose technical details about attacker methods. The compromised data remained under assessment for notification requirements at the time of reporting, with no further operational disruptions disclosed beyond the initial containment.

Sources

Sources available to members: 2 sources.

CSIDB