Menu
Browse
Date:

Jan 2019

Location:

United States of America

Summary

Columbia Surgical Specialists of Spokane experienced a ransomware attack compromising protected health information of approximately 400,000 patients, including files over two decades old. The organization engaged a security firm to restore systems without paying ransom, though the breach prompted reporting to federal regulators due to potential unauthorized access to sensitive data. Patient notification complexities arose from outdated records, with the entity continuing to assess affected individuals while facing scrutiny over data retention practices and security vulnerabilities related to maintaining historical information on internet-connected servers.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On January 7, 2019, Columbia Surgical Specialists of Spokane experienced a ransomware attack impacting its network servers. The incident disrupted access to electronic protected health information (ePHI) stored on the practice’s systems. An information systems manager confirmed to Information Security Media Group that the organization engaged a security firm to unlock its systems and recover its data without paying a ransom. Recovery operations concluded within a few days of the initial attack. The breach affected approximately 400,000 patients, with compromised data including some patient records dating back more than 20 years. Columbia Surgical Specialists formally reported the incident to the U.S. Department of Health and Human Services (HHS) on February 18, 2019, classifying it as a network/IT server breach under HIPAA rules.

Cyber Incident Image

The practice acknowledged challenges in notifying affected individuals due to the age of some records, which included inactive or former patients potentially deceased or unreachable. No substitute notice or public breach notification appeared on the entity’s website despite media inquiries. DataBreaches.net documented unsuccessful attempts to obtain clarification via phone calls regarding data exfiltration risks or the rationale for retaining decades-old ePHI on internet-connected servers. Columbia Surgical Specialists did not publicly confirm whether the incident met HIPAA’s reportable breach criteria or disclose technical details about attacker methods. The compromised data remained under assessment for notification requirements at the time of reporting, with no further operational disruptions disclosed beyond the initial containment.

Sources
Sources available to members
2 sources