Menu
Browse

Cyber Incident Victim: University of Miami Health System

Date

Jan 2023

Location

United States of America

Status

Historical

Timeline
Occurred
Jan 2023
Summary

The University of Miami Health System experienced a breach when an employee's identity theft incident led to unauthorized access to their work email account. Patient names and medical record numbers were compromised after emails containing this information were forwarded to a third-party account. The organization conducted an investigation and notified affected individuals, though no evidence of misuse was identified. The incident highlights risks associated with compromised employee credentials and potential vulnerabilities in account security practices.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around January 3, 2023, the University of Miami Health System (UHealth) disclosed a security incident affecting a limited number of patients. The breach originated from an employee’s personal identity theft incident, which led to unauthorized access to their work-associated University of Miami email account. During the investigation, UHealth determined that emails containing patient names and medical record numbers had been forwarded to a third-party email account without authorization. The health system stated it had no evidence suggesting the compromised information had been misused but issued notifications to inform affected patients of the exposure. UHealth emphasized the incident was contained to a limited scope of patient data, specifically excluding more sensitive details like Social Security numbers, financial information, or clinical records.

Cyber Incident Image

The breach notice did not specify how the employee’s identity theft occurred or whether the employee promptly reported the compromise to UHealth. Questions raised externally centered on whether UHealth required two-factor authentication for email access or had policies mandating employee disclosure of personal device compromises involving work credentials. UHealth did not publicly address these technical or procedural specifics, nor did it confirm whether the identity theft involved additional compromised devices like the employee’s phone. The health system completed its investigation, notified patients, and reiterated recommendations for affected individuals to monitor their medical records for irregularities. DataBreaches.net contacted UHealth for clarification on policy changes or security assessments following the incident but received no response by the article’s publication date. The event highlighted broader concerns about risks posed by infostealers and compromised personal devices storing workplace login credentials in healthcare environments.

Sources
Sources available to members
1 source