CSIDB logo
Incident

Charleston Area Medical Center

Incident posture

Attack window
Jan 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-03-09 19:09

Linked entities

Victim
Charleston Area Medical Center
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jan 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Charleston Area Medical Center experienced a phishing attack where unauthorized actors compromised employee email accounts to collect login credentials, exposing protected health information of approximately 54,000 individuals. The breach involved patient names, medical record numbers, test results, and treatment details, with a minimal fraction of affected individuals having Social Security numbers potentially accessed. The organization secured the impacted accounts promptly after detecting the malicious activity, which targeted credential harvesting rather than direct exploitation of personal data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 10 and 11, 2022, unauthorized actors gained access to several employee email accounts at Charleston Area Medical Center (CAMC) through a phishing attack. The attackers primarily sought to collect employee login credentials rather than target specific patient information. Despite this objective, the compromised email accounts contained protected health information (PHI) belonging to approximately 54,000 individuals. Exposed data included patient names, medical record numbers, test results, and treatment-related information. A very small subset—representing 0.001% of affected individuals—also had their Social Security numbers exposed. CAMC did not specify whether the compromised email accounts were clinical, administrative, or both, nor did they disclose the exact number of accounts breached. The incident was detected through unspecified means, prompting immediate action to secure the affected accounts.

Following the discovery of malicious activity, CAMC secured the compromised email accounts to prevent further unauthorized access. The organization conducted an investigation to determine the scope of the breach and identify affected individuals. Notification letters were subsequently sent to all 54,000 impacted patients, detailing the types of exposed information and offering guidance on protective measures. CAMC did not publicly disclose whether they provided credit monitoring services or other remediation efforts beyond breach notifications. The incident highlighted vulnerabilities in email security protocols, though the organization did not elaborate on specific technical or procedural changes implemented post-incident. No ransomware deployment, data encryption, or financial demands were reported in connection with the phishing campaign. Regulatory filings with the U.S. Department of Health and Human Services confirmed the incident met federal reporting thresholds for breaches affecting over 500 individuals.

Sources

Sources available to members: 2 sources.

CSIDB