Beaver County Behavioral Health says the ransomware found on its systems in July escalated into a data theft, with investigators confirming that files taken from its network included protected health information. The western Pennsylvania agency’s administrator, Lisa McCoy, disclosed the finding on September 4.
The agency detected the ransomware on July 8 and has since worked with federal law enforcement and third-party cybersecurity and data forensics consultants, McCoy said. The review of the incident remains open, and the organization plans to identify which records were involved and where the affected individuals live before mailing written notices.
The wait between discovery and patient letters is common while forensics run, but behavioral health records deserve extra care. HIPAA grants psychotherapy notes stronger protection than most medical data, and Pennsylvania’s own breach rules layer additional duties on providers. Agencies should assume data was taken whenever ransomware appears and have notification templates ready before the scope review ends.