Menu
Browse

Cyber Incident Victim: Wisconsin Institute of Urology

Date:

May 2021

Location:

United States of America

Summary

The Wisconsin Institute of Urology experienced a data breach involving unauthorized access to a compromised employee email account, resulting in the exposure of protected health information. Suspicious activity was initially detected, prompting an investigation that later confirmed the breach and enabled the organization to assess impacted data and initiate patient notifications. The incident's scope remains unclear as it had not yet been publicly reported to federal health authorities at the time of disclosure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The Wisconsin Institute of Urology (WIU) experienced a security incident involving unauthorized access to a protected employee email account. On May 26, 2021, WIU detected suspicious activity associated with the account, prompting an immediate investigation into the nature and scope of the compromise. The organization confirmed on June 9, 2021—fourteen days after initial detection—that unauthorized parties had gained access to the email account. This confirmation enabled WIU to begin assessing the contents of the compromised account to identify affected individuals and determine the specific types of protected health information (PHI) exposed. The breach stemmed directly from the account compromise, though the exact method of initial intrusion was not publicly disclosed.

Cyber Incident Image

WIU initiated notification procedures for impacted patients following its internal review of the breached email account’s contents. The institute did not disclose the number of affected individuals in its public statements, and the incident had not yet appeared on the U.S. Department of Health and Human Services’ breach reporting tool at the time of initial media coverage. The compromised data included PHI, though the precise categories (e.g., medical records, billing details) were not specified in available reports. WIU issued a press release outlining the incident’s discovery timeline and its response efforts, emphasizing its commitment to addressing the breach and safeguarding patient information. No additional technical containment measures or forensic findings were publicly detailed beyond the confirmation of unauthorized access and subsequent notification process.

Sources
Sources available to members
1 source