Menu
Browse

Cyber Incident Victim: RiverKids Pediatric Home Health

Date:

Mar 2022

Location:

United States of America

Summary

An unauthorized individual gained access to multiple employee email accounts at RiverKids Pediatric Home Health, potentially compromising patient information including names, birthdates, addresses, and health insurance member IDs. The Texas-based pediatric home health provider confirmed no exposure of financial data or Social Security numbers, and implemented enhanced email security measures following the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 15, 2022, RiverKids Pediatric Home Health, a Texas-based pediatric home health provider, discovered that an unauthorized individual had gained access to an employee's email account. The organization initiated an investigation into the security incident, which revealed that multiple employee email accounts had been compromised. The review of these accounts confirmed they contained patient information, though the exact method of initial compromise and duration of unauthorized access were not publicly disclosed. The compromised data included patient names, dates of birth, physical addresses, and health insurance member identification numbers. RiverKids determined that financial information such as bank account details and Social Security numbers were not exposed in the breach. The incident affected 3,494 patients whose protected health information was potentially viewed or stolen through the email account intrusions.

Cyber Incident Image

Following the investigation, RiverKids began notifying affected patients about the exposure of their personal and health information. The organization implemented additional email security measures to prevent similar incidents from occurring in the future, though specific technical details of these enhancements were not provided in public communications. No evidence suggested that the compromised information had been misused prior to the notification. The breach did not involve ransomware or encryption of systems, distinguishing it from other contemporaneous healthcare incidents. RiverKids' response focused on securing email systems rather than offering credit monitoring services, as the exposed data types did not include information typically used for financial identity theft. The incident highlighted vulnerabilities in email account security within healthcare organizations handling pediatric patient data.

Sources
Sources available to members
1 source