Phishing attack exposes 54K patient records at West Virginia hospital

Charleston (W.Va.) Area Medical Center notified patients of a January phishing incident that affected 54,000 individuals.

Advertisement

On Jan. 10 and 11, an unauthorized party accessed the email accounts of “a small number of” Charleston Area Medical Center employees through a phishing scam, the hospital said in its notice to patients. Upon learning of the incident Jan. 10, the hospital terminated the unauthorized access and secured the affected email accounts.

Charleston Area Medical Center partnered with a cybersecurity forensics firm for an investigation, which ended March 16. The investigation concluded that the unauthorized individual appeared to be interested in collecting hospital employees’ login information rather than accessing patients’ personal information.

The following types of personal information were found in the employee email accounts: first and last names, medical record numbers and health information such as discharge dates and test results. Additionally, Social Security numbers or financial account numbers were found for less than 0.001 percent of the potentially affected population.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.