MedStar Regional Health, a network of 23 hospitals across the mid-Atlantic region, has disclosed a ransomware attack that compromised the personal health information of approximately 4 million patients. The breach was discovered on April 10 after anomalous network activity triggered automated alerts.
The attackers, believed to be affiliated with the BlackSuit ransomware group, exfiltrated patient names, Social Security numbers, medical histories, and insurance information before encrypting critical systems.
MedStar has engaged federal law enforcement and leading cybersecurity firms to investigate the incident and is offering two years of free credit monitoring and identity theft protection to all affected individuals.