MalwareRansomwareSupply Chain (3P Vendor)Data EncryptedCustomer Data InvolvedRansom DemandedIDENTITY_BASICHEALTH_BASICLowContained
Beebe Medical Center
bd_dafa7a1c267cbd93 · schema v1 · pii pii-v1
Full breach record for Beebe Medical Center →Beebe Medical Center notified Delaware AG of a ransomware attack on its third-party cloud provider, Blackbaud, Inc. The attack occurred between Feb 7 and May 20, 2020. Beebe discovered its data was in the impacted database on Dec 2, 2020. The attacker encrypted data and demanded ransom, which Blackbaud paid. Beebe's data included names, DOBs, clinician names, visit dates, and departments. No SSNs or financial data were impacted. Beebe engaged forensic experts and Blackbaud implemented enhanced security controls.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/01/Beebe-Medical-Center-Ad-r1prf.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 24, 2020
- Raw hash
- d2c89b4c28862f9294a32cee789ef09a7249cdc69ce519784c787ebbbf6a4716
Reporting entity
- Name
- Beebe Medical Centernorm: beebe medical center
Victim entity
- Name
- Beebe Medical Centernorm: beebe medical center
Incident
- Discovered
- Dec 2, 2020
- Materiality determined
- —
- Notification sent
- Jan 15, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Blackbaud, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.