CSIDB logo
Incident

Sunrise Community Health

Incident posture

Attack window
Sep 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-02-03 02:16

Linked entities

Victim
Sunrise Community Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Unauthorized access to employee email accounts at Sunrise Community Health occurred over several months, potentially exposing personal and health-related information including patient names, dates of birth, IDs, provider details, service dates, exam types and results, insurance information, medications, and diagnoses. The organization secured its systems, initiated an investigation with third-party forensic experts, and notified potentially affected individuals while offering complimentary credit monitoring and identity theft restoration services; evidence suggests the perpetrators targeted financial data, though unauthorized access to specific information remains unconfirmed.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Sunrise Community Health in Colorado experienced a data security incident involving unauthorized access to employee email accounts. The organization discovered unusual activity in its email system, leading to an investigation launched on November 5, 2019, which confirmed personal information was present in the compromised accounts. Forensic analysis determined the unauthorized access occurred intermittently between September 11, 2019, and November 22, 2019. Evidence suggested the intruders specifically targeted payroll and invoice-related data, though investigators couldn't conclusively confirm whether any information was actually viewed or exfiltrated. The affected email accounts contained varying combinations of patient information including names, dates of birth, patient identification numbers, provider names, service dates, clinical exam types, general results, health insurance details, medication names, and diagnoses. Sunrise emphasized it had no evidence of actual misuse of the exposed data but initiated notifications out of caution given the sensitive nature of the information involved.

Upon detecting the breach, Sunrise immediately engaged third-party forensic specialists to investigate the incident's scope and secure its email environment. The organization implemented additional security enhancements to its systems while continuing the ongoing investigation. Sunrise notified potentially affected individuals about the exposure of their personal health information and offered complimentary credit monitoring and identity theft restoration services through Kroll for one year. A dedicated assistance line was established to address patient inquiries regarding the incident. The notification advised individuals to monitor account statements and credit reports for suspicious activity while providing protective guidance through Sunrise's website and mailed communications.

Sources

Sources available to members: 1 source.

CSIDB