CSIDB logo
Threat actor

Five Hennepin HealthCare employees

Attribution profile

Type
Insider - Disgruntled
Location
United States of America
Known incidents
1 incident
First seen
2020-10-13
Last seen
2020-10-13
Updated
2026-07-31 03:46
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor referred to as the Five Hennepin HealthCare employees consists of five individuals who were employed by Hennepin HealthCare, a healthcare provider located in the United States of America. They are known publicly by this descriptive alias, which reflects the number of staff members involved and their affiliation with the organization. No other names or alternate identifiers have been associated with this group in the available sources. Their activity is confined to the internal environment of the hospital where they held positions that granted them access to patient medical records. The actor’s location is explicitly noted as the United States, with no indication of operations beyond that jurisdiction.

On October 13, 2020, an internal investigation at Hennepin HealthCare uncovered that these employees had accessed the medical records of George Floyd without authorization or a legitimate work‑related reason. The review determined that the accesses occurred multiple times, indicating repeated violations of patient privacy policies. As a result of the findings, the hospital terminated the employment of several staff members implicated in the improper accesses. The breach involved sensitive health information belonging to a high‑profile patient, which heightened the significance of the incident. The hospital’s response included notifying the family attorney of George Floyd about the unauthorized disclosures.

The disclosure to the family attorney confirmed that the handling of Floyd’s medical data did not comply with applicable privacy regulations and internal safeguards. This acknowledgment underscored the failure of existing controls to prevent unauthorized viewing of confidential records by personnel lacking a justified need. The incident served as a concrete example of how insider privilege can be misused even within a regulated healthcare setting. While no further campaigns or broader operational patterns have been attributed to this group, the case remains a documented instance of insider threat within the U.S. healthcare sector. The episode highlights the importance of monitoring access logs and enforcing strict accountability for employees who handle protected health information.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB