CSIDB logo
Incident

Saint Anthony Hospital

Incident posture

Attack window
Feb 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 16:12

Linked entities

Victim
Saint Anthony Hospital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An unauthorized party obtained access to a limited number of Saint Anthony Hospital employee email accounts, prompting the organization to launch an immediate investigation with third-party cybersecurity professionals and report the matter to law enforcement. While the inquiry remains ongoing, the hospital determined that personal information and protected health information may have been impacted, potentially including full names, addresses, dates of birth, Social Security numbers, dates of service, telephone numbers, medical record numbers, patient account numbers, prescription information, and details regarding medical history, conditions, treatments, or diagnoses. At the time of the notice, there was no evidence that any of the compromised information had been or would be misused for identity theft or medical or financial fraud, and the hospital committed to notifying all known affected individuals in accordance with applicable laws as the investigation progresses.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On or about February 6, 2025, Saint Anthony Hospital in Chicago learned that an unauthorized party may have obtained access to a limited number of Saint Anthony Hospital employee email accounts. Upon learning of this issue, the organization immediately began efforts to remediate the incident and commenced a prompt and thorough investigation. As part of that investigation, the hospital worked very closely with third-party cybersecurity professionals experienced in handling these types of incidents in order to determine the nature and scope of the incident and whether any sensitive data, including personal information and/or protected health information, was accessed and/or acquired by the unauthorized party. Saint Anthony Hospital also reported the incident to law enforcement.

While the investigation remained ongoing at the time of the published notice, Saint Anthony Hospital learned that personal information and/or protected health information may be impacted. The notice states that the types of information potentially involved include full name, address, date of birth, Social Security number, date(s) of service, telephone numbers, medical record number, patient account number, prescription information, and medical history, condition, treatment, or diagnosis. The hospital stated that if it learns that an individual's personal information or protected health information was impacted, it will notify those individuals and all known impacted individuals as quickly as possible, and in accordance with applicable laws. At the time of the notice, Saint Anthony Hospital indicated it had no evidence that any personal information has been or will be misused for identity theft or medical/financial fraud as a direct result of this incident, and stated that the notice was being provided out of an abundance of caution.

The published notice also included a set of recommendations directed at those served by Saint Anthony Hospital, as well as team members, encouraging them to take steps to protect themselves. These recommendations covered placing an initial one-year fraud alert on credit files, considering placing a security freeze on credit files, obtaining free credit reports, and remaining vigilant in reviewing financial account statements and credit reports for fraudulent or irregular activity on a regular basis. The notice additionally provided guidance specifically aimed at protecting health information, advising individuals to share health insurance cards only with health care providers and covered family members, to review explanation of benefits statements, and to request a current year-to-date report from their insurance company of all services paid for them as a beneficiary. Resources offered in the notice included contact information for the Federal Trade Commission's Identity Theft Data Clearinghouse and instructions for filing a police report in the event that suspicious activity is identified.

The notice also included state-specific information for residents of Iowa, Maryland, Massachusetts, New York, North Carolina, Oregon, Washington D.C., New Mexico, and Rhode Island, providing the respective Attorney General contact details and, for several states, additional statutory information about obtaining security freezes, submitting declarations of removal, or filing police reports. For individuals with questions regarding the incident, the hospital designated a dedicated and confidential toll-free response line at 877-580-4384, staffed with professionals familiar with the incident and knowledgeable about protecting against potential misuse of information. The response line was made available from 8:00 a.m. to 5:00 p.m. Central Time, Monday through Friday, excluding holidays.

Saint Anthony Hospital stated in the notice that it is committed to maintaining the privacy of personal information in its possession and has taken many precautions to safeguard it. The organization indicated that it continually evaluates and modifies its practices and internal controls to enhance the security and privacy of the personal information it maintains, and that it was taking significant steps to mitigate the risk to persons impacted by the incident. The published notice did not state the total number of individuals whose information may have been impacted, did not identify the unauthorized party, did not specify the exact date range of unauthorized access to the employee email accounts, and did not describe the technical method used to gain access. The notice did not disclose the duration of the investigation timeline, the specific employee email accounts involved, or whether any particular clinical or administrative systems, beyond the email accounts, were affected.

Sources

Sources available to members: 1 source.

CSIDB