CSIDB logo
Incident

Geisinger Health System

Incident posture

Attack window
May 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-16 00:00

Linked entities

Victim
Geisinger Health System
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Geisinger Health System experienced a data breach due to a ransomware attack on its mail service vendor, KayeSmith, which compromised patient information used for marketing and communications. The incident exposed names, addresses, medical record numbers, dates of service, and payment installment plans, though no misuse of data was reported. The vendor offered credit monitoring services to affected individuals, and the health system collaborated to implement additional safeguards. The breach impacted 2,857 patients.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In late May 2022, KayeSmith, a mail service vendor utilized by Geisinger Health System’s online billing provider VisitPay, suffered a ransomware attack that rendered its systems inaccessible. The attack disrupted marketing and communications operations for Geisinger, a Danville, PA-based healthcare organization. KayeSmith initiated a forensic investigation following the attack, which determined that unauthorized actors potentially accessed and obtained files containing patient information provided by its clients for marketing campaigns. Geisinger was notified of the potential breach in September 2022, approximately four months after the initial attack occurred. The compromised data included patient names, addresses, medical record numbers, dates of service, and details about payment installment plans.

KayeSmith conducted a risk assessment confirming the exposure of sensitive information but found no evidence of actual misuse of patient data at the time of notification. The breach impacted 2,857 Geisinger patients, as reported to the HHS Office for Civil Rights. In response, KayeSmith offered complimentary credit monitoring services to affected individuals. Geisinger collaborated with the vendor to implement additional safeguards aimed at preventing future security incidents. The healthcare system confirmed no operational disruptions to its internal systems, as the compromise was limited to data processed by the third-party vendor for billing-related communications. No identity theft or fraudulent activity linked to the breach had been reported by Geisinger or KayeSmith as of the notification period.

Sources

Sources available to members: 1 source.

CSIDB