St. Clair Orthopaedics and Sports Medicine Data Breach Details
SCOSM first detected suspicious activity within its network on November 24, 2024, prompting an internal investigation. The organization engaged cybersecurity specialists to assess the extent of the intrusion. By December 9, 2024, investigators confirmed that certain network locations containing patient data had been accessed.
After a comprehensive review of the compromised files, which concluded on January 29, 2025, SCOSM determined that patient information was exposed and began notifying affected individuals. Patients are also encouraged to obtain a free credit report from major credit bureaus.
The attack on SCOSM is part of a growing trend of ransomware attacks targeting healthcare providers, where cybercriminals exploit vulnerabilities to steal sensitive medical data. BianLian, the group claiming responsibility, is known for infiltrating organizations and demanding ransom payments to prevent data leaks.
What Information Was Compromised?
According to SCOSM, the compromised information may include:
- Personal Details: Names, addresses, phone numbers, email addresses, and dates of birth.
- Health Insurance Information: Health plan details, insurance companies, policy numbers, and Medicaid/Medicare government payor ID numbers.
- Medical Data: Medical record numbers, physician information, diagnoses, prescriptions, test results, and treatment history.
- Financial and Billing Information: Claim numbers, account balances, billing codes, and payment details.
- Identification Data: Social Security numbers, driver’s license numbers, and other personal identification numbers.