Texas Tech University Health Sciences Center disclosed a ransomware attack in late 2024 attributed to the Interlock ransomware group. Approximately 1.4 million patient records were affected across its Lubbock and El Paso campuses.
Interlock ransomware group gained initial access via phishing targeting clinical research staff. Double-extortion: data exfiltrated to Interlock leak site prior to encryption. Both Lubbock and El Paso campuses affected, suggesting shared network infrastructure.
Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →
| Regime | Standard / Citation | Gap Identified |
|---|---|---|
| HIPAA | 45 CFR §164.308(a)(1) | Risk analysis — multi-campus network architecture not assessed for ransomware propagation risk |
| HIPAA | 45 CFR §164.312(a)(1) | Access control — research staff credentials gave access to clinical systems beyond job function |
| TDPA | Tex. B&C Code §521.053 | 1.4M TX patient notification obligations triggered |
CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.
Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.