CSIDB logo
Incident

Compass Behavioral Health

Incident posture

Attack window
Jul 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-18 00:00

Linked entities

Victim
Compass Behavioral Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Compass Behavioral Health, a Kansas-based mental healthcare provider, experienced a data breach when an unauthorized party accessed files within employee OneDrive accounts and an email account, potentially compromising protected health information of 1,064 patients. The incident involved exposure of names, addresses, dates of birth, treatment locations, medical record numbers, details of medical incidents, limited medical information, and medication data, though no Social Security numbers or financial information were affected. The breach was identified following suspicious email activity, prompting a forensic investigation that confirmed unauthorized access to a spreadsheet containing incident reports. The organization found no evidence of data misuse but advised vigilance to affected individuals.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Compass Behavioral Health, a Kansas-based mental healthcare organization, experienced a data security incident involving unauthorized access to protected health information (PHI). The organization detected suspicious activity within its email environment, prompting it to engage a specialized third-party cybersecurity vendor to conduct a forensic investigation. This investigation revealed that an unauthorized user had gained access to a limited number of files stored in employee OneDrive accounts and one email account. The intrusion potentially exposed sensitive patient data, though the exact timeframe of unauthorized access was not publicly specified in available reports.

On February 14, 2023, forensic experts identified that a specific spreadsheet containing Compass's incident reports had been compromised. This document included records of procedure breaches, injuries, accidents, and unusual events affecting 1,064 patients. Exposed information consisted of names, addresses, dates of birth, dates of death, treatment locations, medical record numbers, details related to medical incidents, limited medical information, and medication data. Investigators confirmed no evidence of Social Security numbers or financial information being accessed. Compass Behavioral Health notified affected individuals and the U.S. Department of Health and Human Services (HHS) about the breach. The organization advised patients to monitor their accounts for suspicious activity but did not report any confirmed misuse of the compromised data at the time of disclosure.

Sources

Sources available to members: 1 source.

CSIDB