Data breach triggered by phishing emails
About 12,000 patients potentially had their personal health information breached due to a phishing scam.
In January, Catholic Health Initiatives (CHI) care systems, based in Tacoma, Wash., learned that phishing emails were sent to a small group of employees from CHI-owned health systems. These employees responded to the emails believing they were legitimate requests from parent company CHI. “When we learned of this, we immediately secured the affected email accounts and began an investigation, including hiring an outside expert forensics firm,” according to CHI.
A subsequent investigation confirmed that a number of employee email accounts had been compromised. The hackers posed as CHI employees to obtain email logins to employee accounts. Forensics research determined that the hackers could have viewed patient demographic information, clinical information, and in a small number of instances Social Security numbers, the health system said.