Full Report
A data breach involving Sandhills Medical Foundation, was reported in April 2026. See incident details, impact on customers, and recommended security measures.
Analysis Summary
# Incident Report: Sandhills Medical Foundation Ransomware Attack
## Executive Summary
Sandhills Medical Foundation suffered a high-severity ransomware attack that compromised the sensitive personal and health information of approximately 169,017 individuals. Although the intrusion was discovered in May 2025, the full extent was not publicly reported until April 2026. The breach resulted in the theft of Social Security numbers, government IDs, and Personal Health Information (PHI), posing a significant risk of identity theft and medical fraud.
## Incident Details
- **Discovery Date:** May 8, 2025
- **Incident Date:** Ongoing/Undisclosed (prior to May 8, 2025)
- **Affected Organization:** Sandhills Medical Foundation
- **Sector:** Healthcare
- **Geography:** United States (South Carolina)
## Timeline of Events
### Initial Access
- **Date/Time:** Pre-May 2025
- **Vector:** Unauthorized third-party intrusion.
- **Details:** An unknown actor gained access to the foundation’s server environment.
### Lateral Movement
- **Details:** Specific lateral movement techniques were not disclosed, but the attacker successfully traversed the environment to reach sensitive servers housing patient and employee data.
### Data Exfiltration/Impact
- **Details:** The attacker encrypted systems (ransomware) and accessed/exfiltrated sensitive records belonging to 169,017 individuals. Data types included Social Security numbers, driver’s licenses, birth dates, passports, and personal health information (PHI).
### Detection & Response
- **Discovery:** The intrusion and ransomware were identified by the organization on May 8, 2025.
- **Response:** The organization initiated an investigation, enhanced security protocols, and notified regulatory bodies. Public reporting and individual notifications were completed by April 28, 2026.
## Attack Methodology
- **Initial Access:** Server Environment Intrusion (Method not specified, likely vulnerability exploitation or credential compromise).
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Not disclosed.
- **Discovery:** Reconnaissance of internal servers containing PHI and PII.
- **Lateral Movement:** Movement from initial entry point to central data servers.
- **Collection:** Gathering of highly sensitive identifiers (SSNs, Passports, Medical Records).
- **Exfiltration:** Transfer of sensitive data to an unauthorized third party.
- **Impact:** Data encryption (Ransomware) and data breach.
## Impact Assessment
- **Financial:** Costs associated with forensic investigation, legal fees, and credit monitoring services for 169,000+ victims.
- **Data Breach:** High-volume exposure of Social Security numbers, government IDs, and PHI (169,017 individuals).
- **Operational:** Disruption of healthcare services due to ransomware encryption on servers.
- **Reputational:** Significant impact due to the delay between discovery (May 2025) and public reporting (April 2026).
## Indicators of Compromise
- **Network indicators:** [sandhillsmedical[.]org - affected domain]
- **File indicators:** Ransomware encryption artifacts (specific strain not identified).
- **Behavioral indicators:** Unauthorized access to server environments; bulk data access/egress.
## Response Actions
- **Containment:** Secured server environment following discovery in May 2025.
- **Eradication:** Investigation into the unauthorized third-party access.
- **Recovery:** Restoration of services; implementation of enhanced security protocols; offering credit monitoring services to affected parties.
## Lessons Learned
- **Reporting Lag:** There was a significant gap (nearly one year) between discovery and final reporting, which increases the window of opportunity for identity thieves.
- **Data Centralization:** High volumes of PII and PHI stored in accessible server environments present a high-value target for ransomware groups.
## Recommendations
- **Identity & Access Management:** Implement phishing-resistant Multi-Factor Authentication (MFA) across all server access points.
- **Data Protection:** Maintain offline, encrypted, and immutable backups to ensure recovery without paying ransoms.
- **Monitoring:** Deploy Attack Surface Management (ASM) tools to identify and close vulnerable entry points.
- **Network Segmentation:** Isolate sensitive PHI/PII databases from general office networks to hinder lateral movement.