Cyber Incident Victim: Englewood Health
Date:
Mar 2022
Location:
United States of America
Summary
An unauthorized third party compromised an employee's credentials at Englewood Health, gaining access to patient data including names, dates of birth, and limited health information affecting nearly 4,000 individuals. The intruder was active for under 40 minutes before being locked out of the network, after which the organization enhanced its physical, administrative, and technical security controls. Impacted patients received notifications and were offered complimentary credit monitoring services as a precautionary measure.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On February 14, 2022, Englewood Health detected that an unauthorized third party had compromised an employee's username and password, granting illicit access to its network. The New Jersey-based health system immediately launched an investigation upon discovering the credential compromise. Forensic analysis revealed the intruder accessed protected patient information during a brief window of unauthorized activity. Within 40 minutes of initial access, Englewood Health's security team identified the breach and successfully locked the threat actor out of the network, preventing further data exposure. The swift containment limited the attacker's operational time within the system before access termination.

The investigation confirmed the unauthorized party obtained identifiable patient information including full names, dates of birth, and limited health details, though the health system emphasized only a restricted subset of records was accessed. A total of 3,901 patients were affected by the data exposure incident. Englewood Health implemented enhanced physical, administrative, and technical security controls across its network infrastructure following the breach to strengthen data protection measures. The organization directly notified all impacted individuals about the compromise of their personal information and provided complimentary credit monitoring services as a precautionary measure despite no evidence of misuse. No ransomware deployment or financial data theft was reported in connection with the incident, which remained confined to the brief February intrusion period.
