Beebe Medical Center notified Delaware AG of a ransomware attack on its third-party cloud provider, Blackbaud, Inc. The attack occurred between Feb 7 and May 20, 2020. Beebe discovered its data was in the impacted database on Dec 2, 2020. The attacker encrypted data and demanded ransom, which Blackbaud paid. Beebe's data included names, DOBs, clinician names, visit dates, and departments. No SSNs or financial data were impacted. Beebe engaged forensic experts and Blackbaud implemented enhanced security controls.