Menu
Browse

Cyber Incident Victim: Hartford HealthCare

Date:

Feb 2020

Location:

United States of America

Summary

Hartford HealthCare experienced a cybersecurity incident involving unauthorized access to two employee email accounts over a two-day period in mid-February, potentially compromising information of up to 2,651 patients. Exposed data included patient names, dates of birth, clinical details, medical record numbers, provider information, and health insurance data, with Social Security numbers accessed for 23 individuals and limited financial information involved for others. The organization secured affected accounts, engaged forensic investigators, mandated password resets for all employees, disabled the attacker's entry software, and reported the incident to federal regulators. No evidence of data misuse was found, and credit monitoring was offered to those whose Social Security numbers were exposed.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Hartford HealthCare experienced a cybersecurity incident between February 13 and February 14, 2020, when unauthorized individuals gained access to two employee email accounts within its network of over 30,000 staff members. The organization detected suspicious activity in these accounts and immediately secured them while engaging a technology forensics firm to investigate the breach. The forensic investigation confirmed the intrusion window and determined that one compromised account contained sensitive patient information. Attackers accessed personal data including patient names, dates of birth, medical record numbers, clinical diagnoses, dates of service, provider names, and health insurance details. For 23 specific patients, the exposed information included insurance account numbers incorporating Social Security numbers, while an undisclosed number of other patients had personal financial information compromised. Hartford HealthCare emphasized that most affected individuals did not have Social Security numbers or credit card information exposed.

Cyber Incident Image

The breach impacted up to 2,651 patients across the healthcare provider's service area covering 185 towns in Connecticut and Rhode Island. Following the investigation, Hartford HealthCare implemented multiple containment measures including mandatory password changes for all employee email accounts and disabling the specific software exploited by the attackers to carry out the compromise. The organization reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights and directly notified affected patients by April 13, 2020. For the 23 patients whose Social Security numbers were exposed, Hartford HealthCare offered two years of free credit monitoring services. The healthcare provider stated no evidence had been found suggesting misuse of any accessed information following comprehensive monitoring of the situation.

Sources
Sources available to members
1 source