Cyber Incident Victim: Saint Alphonsus Hospital
Date:
Sep 2020
Location:
United States of America
Summary
A cybersecurity incident involving Saint Alphonsus Hospital's parent organization compromised patient and donor information through a breach of a third-party service provider's network. The attacker potentially accessed personal data maintained by Blackbaud, which managed the affected systems. The hospital system initiated notifications to impacted individuals via mailed correspondence and stated it was collaborating with the vendor to strengthen security measures. The organization expressed regret for the incident and apologized for resulting concerns, while acknowledging ongoing efforts to notify all affected parties. No operational disruptions to healthcare services were reported in connection with the breach.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In September 2020, Trinity Health, the parent organization of Saint Alphonsus Hospital system, publicly disclosed a data breach potentially compromising patient and donor information. The incident stemmed from a cyberattack targeting Blackbaud, a third-party provider responsible for operating and maintaining Trinity Health’s network infrastructure. Blackbaud confirmed unauthorized actors may have accessed personal data stored within its systems, though the specific timeline of the intrusion and duration of unauthorized access were not detailed in public statements. Trinity Health initiated formal notifications to affected patients and donors via U.S. mail starting September 14, 2020, with plans to continue outreach until all impacted individuals received communication. The organization acknowledged the breach involved sensitive information but did not enumerate specific data elements beyond broadly referencing "personal information." No evidence suggested misuse of the compromised data at the time of disclosure.

Trinity Health collaborated with Blackbaud to implement additional security measures following the breach, though technical specifics regarding containment or forensic investigations were not disclosed. Public communications emphasized ongoing coordination between the entities to strengthen data protections under Blackbaud’s management. The hospital system issued a formal apology to patients and donors, expressing regret for the incident and any resulting concerns or inconveniences. Notifications directed affected parties to a dedicated informational resource for further details but did not outline identity protection services or regulatory reporting actions. The statement concluded by reaffirming Trinity Health’s commitment to its mission while acknowledging community support during the incident. No operational disruptions or clinical care impacts were reported in connection with the breach.
