CSIDB logo
Incident

Memorial Hospital at Gulfport

Incident posture

Attack window
Feb 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-05 00:00

Linked entities

Victim
Memorial Hospital at Gulfport
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A phishing incident at Memorial Hospital compromised an employee email account, exposing personal information of approximately 30,000 patients. The breached data included names, birth dates, medical care details, and health insurance information, with Social Security numbers affected for a limited subset of individuals. The hospital offered free credit monitoring and identity protection services to impacted patients following unauthorized third-party access to the account.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around February 15, 2019, Memorial Hospital at Gulfport disclosed a phishing incident that compromised an employee email account, exposing protected health information of approximately 30,000 patients. Unauthorized third parties gained access to the email account, which contained patient names, dates of birth, medical care details, and health insurance information. A subset of these records included Social Security numbers, though the hospital characterized this more sensitive exposure as affecting a "limited number" of individuals. The hospital did not specify the exact timeframe of unauthorized access or the duration between intrusion detection and public disclosure. Janet Stuart, the hospital's manager of marketing and communications, confirmed the scope of impacted data categories through an official news release.

Memorial Hospital responded by offering complimentary credit monitoring and identity protection services specifically to patients whose Social Security numbers were exposed. The institution published a formal breach notification on its website and coordinated with external media outlets to disseminate information about the incident. No operational disruptions to healthcare services or additional compromised systems beyond the single email account were reported. The hospital did not disclose whether law enforcement agencies were involved in investigating the breach or whether regulatory fines resulted from the incident. Patient data exposure was confined to information contained within the compromised email account, with no evidence suggesting broader network infiltration or data exfiltration through other means.

Sources

Sources available to members: 1 source.

CSIDB