CSIDB logo
Incident

Saint Agnes Health Care

Incident posture

Attack window
Apr 2015
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-15 17:11

Linked entities

Victim
Saint Agnes Health Care
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Saint Agnes Health Care experienced a breach when attackers used a phishing email to compromise an employee's email account, exposing personal information of approximately 25,000 individuals. The compromised data included names, dates of birth, genders, medical record numbers, insurance details, limited clinical information, and Social Security numbers in four instances; the organization disabled the affected account credentials, enhanced security safeguards, notified all impacted parties, and offered identity monitoring services to those whose Social Security numbers were accessed.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 27, 2015, Maryland-based Saint Agnes Health Care disclosed a data breach impacting approximately 25,000 individuals. Attackers compromised an employee's email account through a phishing attack targeting Saint Agnes personnel. The breached account contained stored personal information including names, dates of birth, genders, medical record numbers, insurance details, and limited clinical information. Social Security numbers were exposed in four specific cases. The organization confirmed the attackers gained unauthorized access by deceiving an employee through fraudulent email communications designed to harvest credentials. This phishing method enabled the compromise without requiring direct intrusion into Saint Agnes’s core medical systems or electronic health records.

Saint Agnes responded by immediately disabling the compromised email account’s username and password credentials. The organization initiated implementation of administrative, technical, and physical safeguards to strengthen protections for protected health information. All affected individuals received breach notifications, with those whose Social Security numbers were exposed being offered complimentary identity monitoring and protection services. Saint Agnes reported the incident to its email service provider and announced an evaluation of additional security enhancements to its existing program. Corporate Responsibility Officer Sharon McNamara publicly affirmed these response measures in an official notification posted to the Saint Agnes website, characterizing the organization’s security protocols as robust prior to the incident while acknowledging the need for ongoing improvements in light of the phishing attack’s success.

Sources

Sources available to members: 1 source.

CSIDB