Ransomware

Roper St. Francis Healthcare Ransomware β€” 92K Patients, Charleston SC

πŸ“… 2021-08-01 🏒 Roper St. Francis Healthcare β€” South Carolina hospital system IT systems
Primary Source β†—

Incident Details

On approximately 1 August 2021, Roper St. Francis Healthcare β€” a nonprofit hospital system based in Charleston, South Carolina operating multiple hospitals and medical facilities β€” discovered unauthorised access to its network. Attackers accessed a scheduling application containing patient information. Roper St. Francis filed a breach notification with HHS OCR disclosing that approximately 92,000 patients were affected. Exposed information included patient names, dates of birth, addresses, phone numbers, email addresses, and scheduling/appointment information. Some records also included Social Security numbers, health insurance information, and limited clinical details. Roper St. Francis notified affected patients in September 2021 and offered credit monitoring services. The breach occurred during a period when many healthcare providers were simultaneously dealing with COVID-19 pandemic pressures and a broader wave of healthcare ransomware attacks in mid-2021. Roper St. Francis operates three hospital campuses and numerous outpatient facilities primarily serving the greater Charleston, South Carolina region.

Technical Details

Initial Attack Vector
Ransomware group breached Roper St. Francis Healthcare's network and accessed a scheduling application containing patient demographic and appointment data; the specific initial access vector was not publicly disclosed
Vendor / Product
Roper St. Francis Healthcare β€” South Carolina hospital system IT systems

Timeline

  1. 2021-08-01 Breach occurred
  2. 2021-09-17 Publicly disclosed
  3. 2021-09-17 Customers notified