Full Report
In connection with a July ransomware attack, Beaver County Behavioral Health (“BCBH”) has determined that there was unauthorized access to, and acquisition of, protected health information related to individuals who received services from BCBH. We take this matter very seriously because of our commitment to the privacy and security of all information we maintain. We are providing this notice to inform potentially impacted individuals and suggest ways that individuals can protect their information. What Happened Beginning on July 8, 2026, BCBH detected suspicious activity on our computer network. As soon as we learned this, we began working to investigate and determine the scope of the incident. We also reported this incident to federal law enforcement and worked with nationally recognized third-party cybersecurity and data forensics consultants. As part of the ongoing investigation, we determined that there was unauthorized access to BCBH’s network. During that time, the cyber criminals copied certain data from our network, which included protected health information. We are conducting a thorough review of the impacted data to establish what information may have been involved, who may have been affected, and where those people reside so that we can provide notice. Upon completing our review, we will provide the required written notice to individuals. On September 4, 2026, BCBH mailed notification letters to the identified impacted individuals to date.
Analysis Summary
# Incident Report: Beaver County Behavioral Health Ransomware Attack
## Executive Summary
Beaver County Behavioral Health (BCBH) experienced a ransomware attack in July 2026, leading to unauthorized access and exfiltration of Protected Health Information (PHI). The incident resulted in the compromise of sensitive data including Social Security numbers and medical records for individuals receiving services. BCBH has since engaged third-party forensics, notified law enforcement, and initiated credit monitoring and security hardening measures.
## Incident Details
- **Discovery Date:** July 8, 2026
- **Incident Date:** July 2026
- **Affected Organization:** Beaver County Behavioral Health (BCBH)
- **Sector:** Healthcare / Government Services
- **Geography:** Beaver County, Pennsylvania, USA
## Timeline of Events
### Initial Access
- **Date/Time:** July 2026 (prior to detection)
- **Vector:** Not explicitly disclosed (Standard ransomware entry points likely)
- **Details:** Cybercriminals gained unauthorized access to the BCBH computer network.
### Lateral Movement
- **Details:** The investigation confirmed that once inside, attackers navigated the network to reach locations containing PHI.
### Data Exfiltration/Impact
- **Details:** Cyber criminals copied (exfiltrated) data from the network containing PHI. The attack involved ransomware, suggesting that data was likely encrypted to disrupt operations in addition to being stolen.
### Detection & Response
- **July 8, 2026:** BCBH detected suspicious activity on the network.
- **July – August 2026:** Engagement of third-party forensics and federal law enforcement; ongoing data review to identify affected individuals.
- **September 4, 2026:** Formal notification letters mailed to impacted individuals and public notice issued.
## Attack Methodology
- **Initial Access:** Not disclosed (Commonly Phishing or RDP exploitation).
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Enterprise-wide password resets were required post-incident, suggesting credential compromise.
- **Discovery:** Not disclosed.
- **Lateral Movement:** Confirmed movement to data storage areas.
- **Collection:** Gathering of files containing names, SSNs, and medical history.
- **Exfiltration:** Confirmed copying of data from the network.
- **Impact:** Deployment of Ransomware and unauthorized data acquisition.
## Impact Assessment
- **Financial:** Costs associated with third-party forensics, legal counsel, and credit monitoring services.
- **Data Breach:** Compromise of Name, DOB, SSN, Driver’s license, dates of service, case IDs, medical diagnoses, medications, and insurance claims information.
- **Operational:** Disruption to behavioral health services (implied by ransomware status).
- **Reputational:** Public disclosure required by HHS; potential loss of trust among service recipients.
## Indicators of Compromise
- **Network indicators:** None provided in public notice.
- **File indicators:** None provided in public notice.
- **Behavioral indicators:** "Suspicious activity" detected on the computer network on July 8.
## Response Actions
- **Containment:** Engagement of third-party forensics to isolate the scope.
- **Eradication:** Enterprise-wide password resets performed.
- **Recovery:** Deployment of enhanced detection and response software (EDR/MDR tools).
- **Notification:** Reporting to U.S. Dept. of Health and Human Services (HHS) and federal law enforcement.
## Lessons Learned
- **Visibility:** The gap between the July attack and the September notification suggests a complex data review process was required to identify victims.
- **Detection:** Earlier detection of "suspicious activity" could have potentially mitigated the data exfiltration phase.
## Recommendations
- **Technical:** Finalize deployment of EDR (Endpoint Detection and Response) across all nodes to accelerate future response times.
- **Administrative:** Conduct enterprise-wide staff training on cyber threats and phishing awareness.
- **Data Management:** Implement data minimization and encryption at rest for sensitive PHI to reduce the impact of exfiltration.
- **Monitoring:** Ensure continuous 24/7 monitoring of network logs for anomalies.