CSIDB logo
Incident

UnityPoint Health

Incident posture

Attack window
Mar 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-07-16 17:06

Linked entities

Victim
UnityPoint Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

UnityPoint Health experienced a phishing attack where employees were deceived by emails impersonating an executive, leading to compromised login credentials and unauthorized access to internal email systems. The breach potentially exposed protected health information and personal data of approximately 1.4 million patients through accessed emails and attachments. While unauthorized access occurred, there was no reported misuse of the affected patient information at the time of disclosure.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In March and April 2018, UnityPoint Health experienced a phishing attack compromising employee email accounts and exposing sensitive patient data. Between March 14 and April 3, attackers sent fraudulent emails impersonating a trusted company executive, successfully deceiving employees into disclosing their login credentials. This unauthorized access enabled attackers to infiltrate internal email systems for nearly three weeks. The compromised accounts contained emails and attachments with protected health information and personal details of approximately 1.4 million patients, including standard operational reports used in healthcare administration. UnityPoint Health publicly disclosed the breach in August 2018 through local media outlets and official notices, confirming the attack vector as credential theft through executive impersonation. The organization acknowledged that patient information may have been accessed but emphasized no evidence of actual data misuse had been identified during their investigation.

The incident impacted patient records containing both medical and personal identifiers, though specific data types weren't enumerated beyond general references to protected health information. UnityPoint Health initiated breach notifications to affected individuals and regulatory bodies as required by healthcare privacy regulations. While the organization didn't detail technical containment measures in public statements, the unauthorized access period concluded by April 3, 2018. Security experts cited in media reports highlighted the healthcare sector's vulnerability to such targeted phishing campaigns, particularly those exploiting organizational hierarchies to bypass employee skepticism. The breach underscored operational risks associated with email-based workflows handling sensitive patient data, though UnityPoint Health's disclosure maintained no clinical systems or medical devices were directly compromised beyond the email accounts themselves.

Sources

Sources available to members: 1 source.

CSIDB