Skip to content
The Cyber Security Place

A hospital knew in August and could say what happened in January

Event dated 27 January 2026 · Published 2 September 2026 · 3 sources

A medical centre in Minnesota detected suspicious activity in its systems on 21 August 2025 and confirmed on 27 January 2026 that patient and employee data had been taken. That is 159 days between noticing and being able to say what happened — a second clock, running after detection stops the first one. What was eventually confirmed included names, dates of birth,Social Security numbers, driving licence numbers, insurance details and medical history. Notification to affected people cannot begin until this second clock stops, which is why breach letters routinely arrive months after the intrusion they describe.

The industry measures two intervals and quotes them constantly: how long an intrusion runs before anyone notices, and how long containment then takes. Both are worth measuring and both are well documented. Neither of them is the interval that decides when you find out your medical history is in somebody else's hands.

That interval sits between them and rarely gets a number. Detection tells you something is wrong. It does not tell you which systems were reached, which records were opened, or whether anything left the building — and until those questions have answers, there is nothing specific to tell anybody. This case puts a figure on it, because both dates were published: five months and a week.

Why the second clock runs so long

Establishing what was taken is a different kind of work from noticing that something happened. Noticing can come from a single alert. Establishing scope means reconstructing which accounts were used, what those accounts could reach, and which of those things were actually opened — from logs that were designed to answer operational questions rather than forensic ones, and that frequently do not retain far enough back.

Where the logs run out, the honest answer is that scope cannot be established, and the conservative response is to assume everything reachable was reached. That conservatism is correct and it is expensive: it converts an incident affecting an unknown subset into a notification covering everybody, which is both costlier and less useful to the people receiving the letter.

What it means for the people notified

The categories confirmed here — dates of birth, national insurance identifiers, driving licence numbers — are the ones that cannot be reissued in any practical sense. A payment card is cancelled in a phone call. The rest of that list follows a person for decades, and its value to somebody assembling an identity does not decay while an investigation runs.

Which is the uncomfortable arithmetic of the second clock. The five months spent establishing scope are five months in which the data was already gone and the people concerned did not know to watch for anything. Nothing in the investigation was wrong or slow by the standards of the work; the delay is structural.

The one thing that shortens it

Retention. Not more alerting, not another detection product: logs that go back far enough to answer the question, from the systems that hold the records. An organisation that can reconstruct six months of access to its record system answers the scope question in weeks. One that keeps thirty days of logs on a system holding twenty years of patient histories will be assuming rather than establishing, and the assumption always has to be the pessimistic one.

That is a budget line nobody defends well, because it buys nothing visible until the week it becomes the only thing that matters. It is also the cheapest item on the list, and the only one on this page that shortens the interval between an intrusion and the moment its victims are told.