Cyber Incident Victim: Suncoast Skin Solutions
Date:
Jul 2021
Location:
United States of America
Summary
A Florida-based dermatology clinic network experienced a ransomware attack that compromised sensitive patient data for over 57,000 individuals. The breach exposed names, dates of birth, clinical details, and treatment records, though no confirmed misuse of information occurred. Following detection, immediate containment measures prevented full system encryption, and subsequent forensic investigations confirmed the intrusion scope. The organization migrated patient data to encrypted systems and offered affected individuals complimentary credit monitoring services to mitigate potential risks. Enhanced security protocols were implemented to prevent future incidents.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 14, 2021, Suncoast Skin Solutions, a Florida-based network of 22 dermatological care clinics, detected a ransomware attack targeting its systems. The organization immediately implemented containment measures to prevent full encryption of its infrastructure and engaged a third-party cybersecurity firm to conduct a forensic investigation. This investigation aimed to determine the attack's origin, methods, and scope. The cybersecurity firm completed its forensic analysis on October 14, 2021, after three months of examination. Suncoast then initiated an internal review of its systems to identify whether patient information had been accessed or compromised during the breach. This preliminary system review concluded on November 8, 2021, confirming that unauthorized actors had potentially accessed sensitive data. The organization subsequently contracted a specialized third-party vendor to conduct granular file analysis across affected systems, a process necessary to identify precisely which individuals had their information exposed.

The compromised data included patient names, dates of birth, clinical information, physician notes, and limited treatment details. Suncoast explicitly stated it found no evidence of attempted or actual misuse of the stolen patient data following the breach. In response to the incident, the organization implemented enhanced security protocols, most notably migrating all patient records to an encrypted storage system to reduce future vulnerability. As a remedial measure, Suncoast offered complimentary credit monitoring services to a subset of affected individuals deemed at higher risk of potential identity theft or fraud. The breach impacted 57,730 patients, whose notifications began in early 2022 following the completion of all investigative and file review phases. No technical specifics regarding the ransomware variant, initial attack vector, or duration of unauthorized access prior to detection were disclosed in public reporting.
