Menu
Browse

Cyber Incident Victim: Northwestern Memorial HealthCare

Date:

Feb 2020

Location:

United States of America

Summary

A cybersecurity incident impacting Northwestern Memorial HealthCare originated through a third-party vendor's system compromise, exposing approximately 56,000 records containing donor and patient information. The breach involved unauthorized access to a database backup holding names, demographic details, medical record numbers, service dates, treatment departments, physicians, and limited clinical data, though electronic medical records remained unaffected. Five individuals experienced exposure of highly sensitive information including Social Security numbers and financial account details. The intrusion occurred over several months via the vendor's fundraising software infrastructure without directly targeting the healthcare provider's core systems.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

The Northwestern Memorial HealthCare data breach originated through a third-party vendor, Blackbaud, which provided fundraising database management services. Blackbaud notified Northwestern in mid-July 2020 that an unauthorized individual had accessed its systems between February 7 and May 20, 2020. The attacker potentially acquired a backup database containing donor and patient information associated with charitable contributions. Northwestern clarified that the breach did not directly target its health system infrastructure and confirmed no compromise of its electronic medical record platforms. Exposed data included names, ages, genders, dates of birth, medical record numbers, dates of service, treatment departments, treating physicians, and limited clinical details. Five individuals experienced exposure of highly sensitive information including Social Security numbers, financial account details, and payment card data.

Cyber Incident Image

Northwestern Memorial HealthCare formally reported the incident affecting approximately 56,000 records to the U.S. Department of Health and Human Services. The organization emphasized through spokesperson Christopher N. King that the breach stemmed exclusively from the Blackbaud system compromise. While forensic investigation confirmed the absence of direct infiltration into Northwestern's clinical systems, the incident exposed substantial volumes of protected health information linked to donation activities. No evidence suggested misuse of the accessed data at the time of disclosure. The breach occurred amid a documented industry-wide surge in healthcare hacking incidents, though Northwestern's response focused exclusively on containment through vendor coordination and regulatory compliance measures without disclosing specific remediation steps taken internally.

Sources
Sources available to members
1 source