Menu
Browse

Cyber Incident Victim: Spokane Regional Health District

Date:

Dec 2021

Location:

United States of America

Summary

A phishing incident at Spokane Regional Health District potentially exposed protected health information of over 1,000 individuals when staff opened a malicious email. The health district's IT team promptly investigated and determined that files containing patient data may have been previewed by unauthorized actors, though no evidence confirmed documents were fully accessed, opened, or downloaded. The breach involved possible disclosure of sensitive client information but did not establish confirmed data exfiltration.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 21, 2021, Spokane Regional Health District experienced a data breach involving potential unauthorized access to protected health information. The incident occurred when staff members opened a phishing email, triggering a security event that exposed sensitive patient data. SRHD Information Technology personnel received immediate alerts regarding the suspicious activity, prompting an investigation into the extent of the compromise. Their analysis revealed that files containing client-protected health information might have been "previewed" by unauthorized parties through this email-based attack vector. The breach notification did not specify the exact mechanism by which the phishing attempt enabled potential data viewing, nor did it describe the specific categories of health information involved. Health district officials confirmed the incident impacted more than 1,000 individuals whose personal and medical data resided in the affected systems.

Cyber Incident Image

The subsequent forensic investigation determined no evidence that any documents containing protected health information had been fully opened, accessed, or downloaded by the threat actor. This finding suggested the data exposure might have been limited to partial views through email preview functions rather than wholesale extraction of records. SRHD did not disclose whether the phishing email contained malicious attachments or embedded links that facilitated the potential data preview. The health district's public statement emphasized the possibility of information disclosure rather than confirming actual data theft or misuse. No technical details were provided regarding containment measures, system remediation, or whether multi-factor authentication or other security controls were in place at the time of the incident. The breach notification did not specify whether affected individuals received direct notifications or credit monitoring services following the event.

Sources
Sources available to members
1 source