MalwarePHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Crozer-Keystone Health System (Delaware County, PA)
bd_e3b090b7ca2e27de · schema v1 · pii pii-v1
Full breach record for Crozer-Keystone Health System (Delaware County, PA) →Crozer-Keystone Health System notified Delaware residents of a June 14, 2020 ransomware incident affecting a small portion of hospital data. The attack involved a known ransomware group and resulted in the exfiltration of patient health and personal information, including names, DOBs, SSNs, and lab results. The malware was isolated, systems restored, and all stolen data recovered. The organization engaged forensic investigators, enhanced security controls, and offered one year of free credit monitoring.
Leak gap clock⏱ Leak >90d11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by revil about this victim predates this filing by 92 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_345d0588be0850f8Leak Siterevilfiled 2020-06-01(92d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_b9f11fdc5991ca6bMontana State AGfiled 2020-09-30(29d gap)Verified by operator
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2020/11/Crozer-Master-Notice-to-Customers.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 1, 2020
- Raw hash
- 5950eeb79210e204e541810204830dae4f6592138924ceefa88e2f69ee0464db
Reporting entity
- Name
- Crozer-Keystone Health System (Delaware County, PA)norm: crozer keystone health system delaware county
Victim entity
- Name
- Crozer-Keystone Health System (Delaware County, PA)norm: crozer keystone health system delaware county
Incident
- Discovered
- Jun 14, 2020
- Materiality determined
- —
- Notification sent
- Sep 1, 2020
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.