Cyber Incident Victim: Northwestern Memorial HealthCare
Date:
Feb 2020
Location:
United States of America
Summary
A cybersecurity incident impacting Northwestern Memorial HealthCare originated through a third-party vendor's system compromise, exposing approximately 56,000 records containing donor and patient information. The breach involved unauthorized access to a database backup holding names, demographic details, medical record numbers, service dates, treatment departments, physicians, and limited clinical data, though electronic medical records remained unaffected. Five individuals experienced exposure of highly sensitive information including Social Security numbers and financial account details. The intrusion occurred over several months via the vendor's fundraising software infrastructure without directly targeting the healthcare provider's core systems.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The Northwestern Memorial HealthCare data breach originated through a third-party vendor, Blackbaud, which provided fundraising database management services. Blackbaud notified Northwestern in mid-July 2020 that an unauthorized individual had accessed its systems between February 7 and May 20, 2020. The attacker potentially acquired a backup database containing donor and patient information associated with charitable contributions. Northwestern clarified that the breach did not directly target its health system infrastructure and confirmed no compromise of its electronic medical record platforms. Exposed data included names, ages, genders, dates of birth, medical record numbers, dates of service, treatment departments, treating physicians, and limited clinical details. Five individuals experienced exposure of highly sensitive information including Social Security numbers, financial account details, and payment card data.

Northwestern Memorial HealthCare formally reported the incident affecting approximately 56,000 records to the U.S. Department of Health and Human Services. The organization emphasized through spokesperson Christopher N. King that the breach stemmed exclusively from the Blackbaud system compromise. While forensic investigation confirmed the absence of direct infiltration into Northwestern's clinical systems, the incident exposed substantial volumes of protected health information linked to donation activities. No evidence suggested misuse of the accessed data at the time of disclosure. The breach occurred amid a documented industry-wide surge in healthcare hacking incidents, though Northwestern's response focused exclusively on containment through vendor coordination and regulatory compliance measures without disclosing specific remediation steps taken internally.
