25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Aging Agency Reports Ransomware Attack: 8,750 Patients Impacted

The Ottawa-based East Central Kansas Area Agency on Aging (ECKAAA) has experienced a ransomware attack that has resulted in the encryption of files on one of the agency’s servers. Those files contained the protected health information (PHI) of 8,750 patients.

The attack occurred on September 5, 2017 and was immediately recognized by ECKAAA, which took prompt action to limit the spread of the infection. As a result, only parts of the server had files encrypted. Those files were discovered to contain names, telephone numbers, addresses, birthdates, Medicaid numbers, and Social Security numbers.

ECKAAA hired a cybersecurity firm to assist with the investigation and determine the true extent and nature of the attack. The investigation revealed the ransomware variant used was a variant of Crysis/Dharma – a ransomware variant known to encrypt files stored locally, on mapped network drives, and unmapped network shares. Crysis/Dharma ransomware also deletes shadow volume copies to hamper recovery.

While the investigation uncovered no evidence of exfiltration of data, the possibility of data access and data theft could not be ruled out. ECKAAA reports that while not all files on the server were encrypted, the attackers potentially had access to all files saved on the server.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Prior to the ransomware attack, ECKAAA had implemented safeguards to protect against malware attacks and to ensure files could be recovered in the event of disaster. Consequently, it was possible to recover all the encrypted files without paying the ransom.

Since the protections in place were not sufficient to block the ransomware attack on this occasion, ECKAAA has implemented a number of new measures to improve security. Those measures include the use of CrowdStrike advanced malware agents and subscription to Cisco Umbrella Insights to improve security monitoring.

Additional training has also been given to staff to improve awareness of the threat from ransomware, a full password reset has taken place, and staff have been reminded about the importance of selecting strong passwords. A review of policies and procedures is also taking place and they will be updated accordingly to reduce the risk of future attacks occurring.

ECKAAA conducted a fully HIPAA-compliant breach response. The incident was reported to the Department of Health and Human Services’ Office for Civil Rights, a substitute breach notice was placed prominently on the ECKAAA website, and media reports were submitted to prominent newspapers serving each of the five counties in which the agency operates. All individuals have now been notified of the potential breach of their PHI by mail.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist