Cyber Incident Victim: Sparta Community Hospital District
Date:
Mar 2023
Location:
United States of America
Summary
An unauthorized individual gained access to an employee email account at Sparta Community Hospital District. The breach occurred over a two-day period and was discovered shortly thereafter. The compromised account contained protected health information including patient names, addresses, phone numbers, dates of birth, medical record numbers, physicians' names, medical diagnoses, and limited treatment details. The hospital confirmed that no financial information or Social Security numbers were affected. Following the incident, the email account was secured and affected individuals are being notified.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 28, 2023, the Sparta Community Hospital District in Illinois identified suspicious activity occurring within an employee email account, prompting the immediate launch of an internal investigation to determine the nature and scope of the incident. The subsequent forensic analysis revealed that an unauthorized individual, characterized as a hacker, had successfully gained access to the compromised email account. This access was not a prolonged campaign but a specific intrusion that occurred over a two-day period, beginning on March 27 and concluding on March 28, 2023. The investigation confirmed that the protected health information contained within the email account was the primary target and was exposed to the unauthorized party. The hospital district moved to secure the affected email account to prevent any further unauthorized access following the discovery of the breach.

The compromised email account contained a range of sensitive patient information, though the specific number of affected individuals was not publicly disclosed by the hospital. The data exposed included patient names, their physical addresses, phone numbers, and dates of birth. Furthermore, medical record numbers, the names of attending physicians, medical diagnosis information, and limited details regarding patient treatments were also accessed. The hospital explicitly stated that no financial information, such as credit card or bank account numbers, and no Social Security numbers were involved in this particular security incident. As part of its response, Sparta Community Hospital District took action to notify all individuals whose protected health information was contained within the breached email account, in accordance with regulatory requirements. The hospital’s public statement confirmed that the email account had been secured as a direct result of the incident.
