Menu
Browse

Cyber Incident Victim: Nevada Health Centers

Date:

Nov 2020

Location:

United States of America

Summary

Nevada Health Centers experienced unauthorized access to an employee's email account over a multi-week period, with the intrusion believed to target financial information rather than protected health data. The organization could not definitively confirm whether patient information was accessed or exfiltrated, creating uncertainty about potential risks to affected individuals. While notification efforts were initiated, the scope of impacted patients remains unspecified due to inconclusive forensic findings regarding data compromise.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 20, 2020, Nevada Health Centers discovered unauthorized access to an employee’s email account. The breach persisted until December 7, 2020, when the unauthorized activity was terminated. The organization initiated an investigation but could not conclusively determine whether patient data was accessed or exfiltrated during the intrusion period. Nevada Health Centers stated the attacker’s primary motivation appeared to target financial information related to the organization rather than protected health information (ePHI). Despite this assessment, the entity acknowledged that patient data stored within the compromised email account could have been exposed. Notifications were issued to an undisclosed number of affected patients, though the organization did not publicly specify the exact scope of individuals impacted.

Cyber Incident Image

The breach disclosure contained ambiguous language regarding the potential risks to patients, making it difficult for recipients to evaluate their personal exposure. Nevada Health Centers did not clarify whether forensic analysis confirmed actual data theft or merely confirmed unauthorized access to the email environment. No details were provided about the types of patient information potentially accessible in the email account, such as medical records, identifiers, or financial data. The incident timeline suggests a 17-day period between initial compromise and containment, with no public information available about detection methods or remediation steps taken. Nevada Health Centers’ communication emphasized uncertainty about the attacker’s intent while maintaining that ePHI was not the presumed target.

Sources
Sources available to members
1 source