
The protected health information (PHI) of nearly 300k heart patients at South Denver Cardiology Associates (SDCA) has been exposed in a cyberattack, which took place on January 4, 2022.
According to the healthcare provider’s privacy incident notice issued to its patients, the unknown perpetrator(s) gained access to files containing information on 287,652 patients during the attack.
Upon identifying unusual activity within the computer network, SDCA immediately initiated its incident response process, which included taking steps to isolate the network by shutting off computer systems. It also began an investigation with the assistance of a computer forensic firm and notified law enforcement.
The investigation determined that the hackers had access to certain systems from January 2, 2022, to January 5, 2022. The files accessed in the attack contained patient information, including Social Security numbers and/or drivers’ license numbers, names, dates of birth, health insurance information, patient account numbers, and clinical information, such as dates, types of service, and diagnoses and physician names.
After a comprehensive review, SDCA said the contents of patient medical records were unaffected, and the patient portal was not compromised. The investigation did not discover any evidence of actual or attempted misuse of patient information.
However, as a precaution, SDCA began mailing letters to our patients on March 4, 2022, including guidance to protect their information and details on an offer of complimentary credit monitoring and identity protection services.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543