Menu
Browse
Date

Jan 2019

Location

United States of America

Status

Historical

Timeline
Occurred
Jan 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

Verity Medical Foundation experienced a third unauthorized access incident involving employee email accounts, compromising protected health information for over 14,000 patients. The breach was detected within hours, mirroring two prior similar incidents disclosed shortly beforehand. In response, the organization implemented enhanced security measures including mandatory password resets, disabled unknown URLs, conducted targeted employee re-education, and deployed new organization-wide cybersecurity training modules. Four distinct notification templates were used to inform affected individuals of the breach.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On January 16, 2019, Verity Medical Foundation experienced a third unauthorized access incident involving an employee's email account containing protected health information (PHI), occurring less than two weeks after disclosing two similar breaches in January 2019. The intrusion was detected within hours of occurrence, mirroring the rapid discovery timeline of the prior incidents. The compromised email account stored or had attachments containing PHI, though the specific data elements or attacker methods were not disclosed. This event impacted over 14,000 patients, as subsequently listed on the HHS breach reporting tool in March 2019. The breach represented a recurring pattern, as all three January 2019 incidents involved employee email account compromises exposing PHI through identical attack vectors. No evidence suggested prolonged access or systemic network infiltration beyond the targeted email accounts.

Cyber Incident Image

Verity Medical Foundation responded by implementing corrective measures including individualized counseling and security re-education for involved personnel. The organization deployed a new mandatory training module for all employees and initiated security enhancements, notably system-wide password resets and the disabling of unknown URLs. Four distinct notification letter templates were issued to affected parties, though the specific content variations or recipient segmentation criteria were not detailed. The foundation did not disclose whether forensic investigations linked the three January breaches to a common threat actor or whether regulatory penalties were imposed. The cumulative impact of these incidents revealed persistent vulnerabilities in email account security practices despite prior remediation efforts.

Sources
Sources available to members
1 source