ResourcesTexas Breach Tracker › Fort Worth Brain & Spine Institute
Healthcare Ransomware Remediated

Fort Worth Brain & Spine Institute
Breach Analysis

Fort Worth Brain & Spine Institute disclosed a ransomware attack in February 2025 affecting 89,000 patients. PHI including diagnosis codes, treatment records, and insurance information was compromised.

Incident Date
2025-02-28
Records Exposed
89,000
Attack Type
Ransomware
Threat Actor
Unconfirmed

How they got in

Ransomware delivered via phishing targeting billing department. Credential compromise led to EMR and billing system encryption. Sensitive neurology and spine diagnosis codes in exfiltrated data.

Sentinel / Fortress / Command coverage

Sentinel Healthcare phishing detection: billing department is highest BEC/ransomware risk in specialty practices; enhanced email monitoring for this user group
Fortress EDR on billing workstations: ransomware process tree killed at execution stage before EMR encryption begins
Command HIPAA compliance: sensitive diagnosis code data classified; access restricted to treating providers only — billing staff cannot access clinical diagnosis details

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
HIPAA 45 CFR §164.308(a)(5) Security awareness — billing staff targeted by phishing; no documented simulation program
HIPAA 45 CFR §164.312(a) Access control — billing staff had access to clinical diagnosis records beyond minimum necessary
TDPA Tex. B&C Code §521.053 89,000 TX patient notifications required

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.