CSIDB logo
Incident

Penn Highlands Brookville

Incident posture

Attack window
Nov 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-17 10:22

Linked entities

Victim
Penn Highlands Brookville
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A healthcare provider experienced a data breach impacting patients of a specific physician when a third-party vendor hosting patient records was compromised. The incident affected 4,500 individuals but did not directly involve the provider's systems or the physician's own infrastructure. The vendor responsible was identified as M&M Computer Services, an Ohio-based firm tasked with managing the affected records.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In October 2014, Penn Highlands Brookville (PHB) in Pennsylvania disclosed a cybersecurity incident involving unauthorized access to patient records associated with Dr. Barry Snyder’s practice. The breach did not originate from PHB’s own systems or directly impact Dr. Snyder’s operations but instead stemmed from a compromise at an unnamed third-party vendor responsible for hosting the affected patient data. At the time of the initial disclosure, PHB provided limited details about the incident, declining to identify the external service provider or specify the number of individuals impacted. The lack of immediate transparency left patients and stakeholders with unresolved questions about the scope and responsible parties involved in the breach.

Updated information emerged on November 7, 2014, when PHB’s breach appeared in the U.S. Department of Health and Human Services (HHS) public breach reporting tool. This filing confirmed M&M Computer Services, an Ohio-based firm, as the compromised third-party vendor entrusted with storing Dr. Snyder’s patient records. The incident affected 4,500 patients, all of whom received breach notifications following the investigation. The disclosure through HHS marked the first official acknowledgment of both the vendor’s identity and the scale of impacted individuals. No additional technical details about the attack vector, data exfiltration methods, or containment measures were publicly released by PHB or M&M Computer Services. The incident underscored the risks associated with third-party data management in healthcare and highlighted delays in initial breach transparency.

Sources

Sources available to members: 1 source.

CSIDB