Menu
Browse

Cyber Incident Victim: Billings Clinic

Date:

Feb 2018

Location:

United States of America

Summary

A healthcare provider experienced unauthorized access to its email system, impacting patients who utilized the pharmacy at its main campus. The breach involved limited email accounts containing patient names, dates of birth, phone numbers, and amounts owed, but excluded sensitive financial or insurance details. Following detection of unusual email activity, the organization engaged a digital forensics firm to investigate, blocked compromised accounts, and implemented enhanced security measures. Affected individuals were notified, and the incident was reported to law enforcement. The provider emphasized ongoing investments in cybersecurity technology and staff training to address evolving threats, noting no evidence of misuse of the exposed information.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In February 2018, Billings Clinic detected unusual activity within its email system, prompting an internal investigation. The organization engaged a national digital forensics firm to determine the source and scope of the unauthorized access. By mid-April 2018, the investigation concluded that an unauthorized individual had viewed a limited number of employee email accounts containing patient information. The breach exclusively affected individuals who accessed or used the pharmacy at the hospital's main downtown campus located at 2800 10th Ave. N. in Billings. Compromised data included patient names, dates of birth, phone numbers, and amounts owed to the pharmacy, but notably excluded highly sensitive information such as Social Security numbers, credit card details, banking information, or insurance data. Hospital spokesman Luke Kobold emphasized that the impacted patients represented only a small fraction of the organization's overall patient database. The incident did not involve compromise of Billings Clinic's electronic medical record systems or financial systems.

Cyber Incident Image

Upon confirming the breach, Billings Clinic immediately blocked unauthorized access to the affected email accounts and implemented additional security measures across all email accounts. The organization mailed notification letters to all impacted patients, providing details about the incident and suggesting steps to monitor personal information. Clinic officials found no evidence that any exposed information had been misused or could be misused following the breach. As part of their response protocol, Billings Clinic reported the incident to the Federal Bureau of Investigation (FBI) and reiterated their ongoing investments in cybersecurity technology and employee education programs. Kobold publicly acknowledged the evolving nature of global cyber threats and the necessity for constant vigilance in healthcare data protection.

Sources
Sources available to members
1 source