25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Advocate Aurora Health, Jefferson Health, and Intermountain Healthcare Affected by Elekta Ransomware Attack

Three more healthcare providers have announced they have been affected by the recent ransomware attack on the Swedish radiation therapy and radiosurgery solution provider Elekta Inc.

Elekta provides a cloud-based mobile application called SmartClinic, which is used by healthcare providers to access patient information for cancer treatments. Cybercriminals gained access to Elekta’s systems between April 2, 2021 and April 20, 2021 exfiltrated the SmartClinic database prior to deploying ransomware and encrypting files. The database contained the personal and protected health information (PHI) of patients of 42 healthcare systems in the United States. Elekta notified affected customers in May 2021.

Advocate Aurora Health has recently announced that 68,000 of its patients across 7 sites in Illinois have been affected by the attack. The following types of PHI were acquired by the ransomware gang: names, addresses, dates of birth, height and weight measurements, Social Security numbers, driver’s license numbers, diagnosis information, treatment information, and appointment confirmations.

Advocate Aurora Health said no evidence has been found to suggest information obtained in the attack has been misused, but complimentary credit monitoring, fraud consultation, and identity theft restoration services have been offered to affected individuals as a precaution. Advocate Aurora Health said it has been working with Elekta to ensure steps are taken to prevent similar events in the future.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Philadelphia, PA-based Jefferson Health said the database contained the PHI of cancer patients who received treatment at its Sidney Kimmel Cancer Center. Patient names, dates of birth, medical record numbers, physician names, department, date(s) of service, treatment plans, diagnosis and/or prescription information were compromised. For some patients, a Social Security number was also included in the database. Patients are being notified by mail and have been offered complimentary credit monitoring and identity theft protection services. Jefferson Health said it is now re-evaluating its relationship with Elekta. Jefferson Health has not yet disclosed how many patients were affected.

Intermountain Healthcare in Salt Lake City, UT said patient names and scanned image files were potentially compromised. The image files included data such as medical intake forms and medical images, which may have included dates of birth, demographic information, insurance cards, other identification cards, and Social Security numbers. Intermountain Healthcare has been working with Elekta to implement additional safeguards, including migrating its data to a new-generation Elekta cloud system. The 28,628 affected patients have been offered complimentary credit monitoring services.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist