Menu
Browse

Cyber Incident Victim: South Shore Health

Date:

Dec 2021

Location:

United States of America

Summary

South Shore Hospital experienced a cyberattack involving unauthorized network access, leading to potential exposure of protected health and employee information for over 115,000 patients. The compromised data included names, addresses, Social Security numbers, medical diagnoses, insurance details, and financial records. Following containment of the incident, the organization engaged forensic experts to investigate and implemented enhanced security protocols such as multifactor authentication, strengthened password policies, and additional anti-phishing tools. Affected individuals were offered complimentary credit monitoring services alongside identity theft insurance and recovery support.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 10, 2021, South Shore Hospital in Chicago detected suspicious activity on its network, prompting immediate containment actions and activation of emergency protocols to sustain safe patient care operations. The hospital engaged third-party computer forensics specialists to investigate the security breach, confirming unauthorized access to network segments storing protected health information (PHI) and employee data. The compromised files contained patient names, addresses, dates of birth, Social Security numbers, health insurance details, medical diagnoses, Medicare/Medicaid identifiers, and financial information. Forensic analysis determined the attackers exfiltrated data belonging to 115,670 current and former patients. No specific technical intrusion vector or attacker identity was disclosed in public notifications. The breach investigation concluded that the accessed systems housed sensitive clinical and administrative records, though the hospital did not report evidence of data misuse following the incident.

Cyber Incident Image

South Shore Hospital initiated patient notifications in February 2022, offering affected individuals a 12-month complimentary membership to IDX credit monitoring and CyberScan services. The remediation package included $1 million identity theft reimbursement insurance and access to identity theft recovery support. Internally, the hospital announced implementation of enhanced security controls: strengthened password policies, multifactor authentication deployment, and supplementary anti-malware and anti-phishing tools. Workforce retraining on data privacy and security protocols was concurrently mandated. Operational continuity measures enacted during the incident remained active until full system integrity was restored, though no care disruptions were reported. The institution did not disclose regulatory penalties or litigation outcomes stemming from the breach in available public statements.

Sources
Sources available to members
1 source