Healthcare Ransomware Attacks: 3 Florida Cases to Know

In 2019, we saw the most cases of ransomware attacks we’d seen in a long time. However, in 2020, with the rise of COVID-19 and the vulnerabilities it brought, the numbers weren’t projected to improve — and they didn’t. By the end of November, more than a dozen large healthcare organizations had been affected by cyber attacks — two of them in Florida. If large organizations are at risk of cyber attacks, it’s not hard to imagine that small businesses are just as vulnerable, if not more so.

ACTS Attack

A cyber attack on Tampa’s Agency for Community Treatment Services, Inc. (ACTS) that began October 21, 2020 was detected on October 23 when ransomware was deployed into their systems and encrypted data to prevent access. These systems contained patient names, dates of birth, Social Security numbers, and medical records holding information related to services provided to patients between 2000 and 2013. Due to the extensive efforts made by the attackers to conceal their activity, the investigation did not uncover any concrete evidence to show patient data had been accessed or stolen. However, this remains a possibility. ACTS was able to restore the encrypted data from backups and did not pay the ransom. Steps have continually been taken post-breach to strengthen security and prevent further attacks, along with providing complimentary credit monitoring and identity theft protection services to all affected individuals.

Leon Medical Centers Attack

Another ransomware attack still being investigated was on Leon Medical Centers, a network of 8 medical centers in South Florida. Prior to deploying ransomware, the attackers threatened to publish patient information publicly if their ransom demands were not met. They claimed to have obtained over 1 million patients’ medical records, names, addresses, Social Security numbers, and even photographs, among other identifying information. This claim, however, was found to be exaggerated. The attack, which occurred prior to December 23, 2020, was still under investigation at the time of this writing, and it was not yet clear how many people were affected.

Proliance Surgeons Attack

Proliance Surgeons in Seattle, WA also suffered a cyberattack on their corporate website in which patient credit card information may have been obtained by the attackers. No other protected health information was involved, and the credit card information at risk only belonged to patients who paid for their services online. The attackers had access to the website between November 13, 2019 and June 24, 2020 according to an investigation. The cause of the breach has since been identified and addressed, and a new website with a different — and more secure — payment platform has been implemented. Proliance has also coordinated with the major payment card providers to prevent unauthorized charges on the affected cards.

What Does This Mean for Us?

With ransomware remaining the biggest cybersecurity threat to healthcare organizations, these attack trends are a reminder of the urgent need for proactive security measures. HIPAA-compliant security frameworks and robust data backup strategies — like the ones ACTS relied on to avoid paying a ransom — are no longer optional for healthcare practices of any size. As we’ve seen with more recent attacks like the Change Healthcare breach, the consequences for unprotected organizations continue to grow. Investing in extensive cybersecurity measures is crucial to keep individuals and organizations safe from malicious attacks such as these. Our network security solutions will help prevent attacks — from hacking to unauthorized access — and keep your business and its data protected. Contact WheelHouse IT today or call us at (877) 771-2384 to schedule a consultation. And download our Ultimate Cybersecurity Checklist below — an easy-to-follow resource to help you identify gaps and protect your data and devices.
wheelhouse it ultimate cybersecurity checklist — click to download