Cyber Incident Victim: University of Miami Health System
Date
Jan 2023
Location
United States of America
Status
Historical
Timeline
Summary
The University of Miami Health System experienced a breach when an employee's identity theft incident led to unauthorized access to their work email account. Patient names and medical record numbers were compromised after emails containing this information were forwarded to a third-party account. The organization conducted an investigation and notified affected individuals, though no evidence of misuse was identified. The incident highlights risks associated with compromised employee credentials and potential vulnerabilities in account security practices.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around January 3, 2023, the University of Miami Health System (UHealth) disclosed a security incident affecting a limited number of patients. The breach originated from an employee’s personal identity theft incident, which led to unauthorized access to their work-associated University of Miami email account. During the investigation, UHealth determined that emails containing patient names and medical record numbers had been forwarded to a third-party email account without authorization. The health system stated it had no evidence suggesting the compromised information had been misused but issued notifications to inform affected patients of the exposure. UHealth emphasized the incident was contained to a limited scope of patient data, specifically excluding more sensitive details like Social Security numbers, financial information, or clinical records.

The breach notice did not specify how the employee’s identity theft occurred or whether the employee promptly reported the compromise to UHealth. Questions raised externally centered on whether UHealth required two-factor authentication for email access or had policies mandating employee disclosure of personal device compromises involving work credentials. UHealth did not publicly address these technical or procedural specifics, nor did it confirm whether the identity theft involved additional compromised devices like the employee’s phone. The health system completed its investigation, notified patients, and reiterated recommendations for affected individuals to monitor their medical records for irregularities. DataBreaches.net contacted UHealth for clarification on policy changes or security assessments following the incident but received no response by the article’s publication date. The event highlighted broader concerns about risks posed by infostealers and compromised personal devices storing workplace login credentials in healthcare environments.
