Cyber Incident Victim: Frederick Regional Health System
Date:
Jan 2019
Location:
United States of America
Summary
Frederick Regional Health System experienced a phishing incident where an unauthorized individual accessed an employee email account, potentially compromising hospice patients' personal and protected health information, including names, health insurance details, and in some cases Social Security numbers. The breach affected a subset of hospice patients receiving services during a specific period, with no evidence of data misuse identified; the organization secured the account, notified impacted individuals, established a dedicated call center, and offered complimentary credit monitoring while reinforcing cybersecurity measures and staff training.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Frederick Regional Health System discovered unauthorized access to an employee's email account on January 21, 2019, resulting from a phishing attack. The organization immediately secured the compromised account and initiated an investigation to determine the scope of the incident. The investigation revealed that the email account contained protected health information of certain hospice patients who received services between June 2017 and January 2019. Exposed data included patient names, health insurance types, health insurance identification numbers, and in some cases, Social Security numbers. The breach did not impact all system patients or even all hospice patients, only a subset within the specified timeframe. There was no evidence suggesting misuse of the compromised information at any point during or after the incident.

The health system mailed notification letters to affected individuals on March 18, 2019, advising them to review insurance statements for unauthorized charges. A dedicated call center (1-844-582-5075) operated weekdays from 8 a.m. to 5 p.m. was established to address patient inquiries, with instructions for non-recipients to contact them by April 11, 2019. Eligible patients received complimentary one-year credit monitoring and identity protection services. Frederick Regional acknowledged prior cybersecurity investments and committed to implementing additional security enhancements while expanding staff email training programs. The organization expressed regret for potential patient concerns but emphasized no evidence of data misuse had been detected through their investigation.
