Lake Washington Vascular restored from backups after Qilin ransomware attack

Organization
Lake Washington Vascular
Exploit
Ransomware
Industry
Healthcare

Lake Washington Vascular, a vascular surgery practice with offices in Bellevue, Kirkland and Issaquah, Washington, was attacked shortly before 5 a.m. on February 14, 2025. Alerts flagged an unauthorized party attempting to install malware, and although the practice's technology team intervened, ransomware encrypted its electronic health record and practice management systems.

The Qilin ransomware group claimed the attack on its leak site and demanded payment. Lake Washington Vascular said it did not pay, and instead restored its files from secure off-site backups with minimal loss of information.

The practice's review found that the information likely involved included names, dates of birth, addresses, diagnostic test results, medical histories, diagnosis and treatment details, payer identification numbers and government-issued identifiers. It said credit and financial information was not stored in the affected systems.

The incident was reported to the US Department of Health and Human Services as affecting 21,534 individuals. Lake Washington Vascular posted a notice on its website on March 10, 2025 and mailed letters to those involved. A law firm investigating the breach put the number of patients whose records sat on the compromised systems at roughly 30,000, higher than the total filed with regulators.

Sources