BlackSuit ransomware listed Kansas City Hospice and Palliative Care

Organization
Kansas City Hospice & Palliative Care
Exploit
Ransomware
Industry
Healthcare

Kansas City Hospice & Palliative Care, a Missouri nonprofit providing end-of-life and palliative care across the Kansas City area, was added to the BlackSuit ransomware group's victim list on October 19, 2024.

The organization said it had identified unusual activity on some of its IT systems and immediately launched an investigation with the help of third-party forensic investigators to understand the extent and scope of the unauthorized activity. Some systems were affected, but it said it remained operational throughout, continued to provide services to patients, and had since fully recovered.

BlackSuit, a successor to the Royal ransomware operation, claimed on its leak site to hold more than 600 GB of material taken from the nonprofit, described as user data, business data, employee data, financial data and other data. Publication on a leak site normally indicates a ransom demand went unpaid. The hospice did not confirm the group's figures or characterization of the stolen data.

The scale became clearer two months later. On December 20, 2024 Kansas City Hospice filed a breach report with the US Department of Health and Human Services Office for Civil Rights covering 3,621 individuals whose protected health information may have been involved, a far smaller number than the volume of data the attackers claimed to hold. The organization, founded in 1980, said it had completed its recovery and was taking steps to strengthen its security. The exact date the attack occurred and the precise categories of data compromised were never disclosed publicly.

Sources