CSIDB logo
Incident

Aspire Health

Incident posture

Attack window
Sep 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-28 00:00

Linked entities

Victim
Aspire Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Aspire Health, a healthcare provider operating across multiple states, experienced a cybersecurity breach resulting from a phishing attack that compromised its internal email system. The unauthorized actor forwarded over 120 emails containing proprietary business details and protected patient health information to an external account. The incident led to the exposure of confidential data, though the full scope of impacted individuals was not publicly detailed in initial disclosures.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 3, 2018, Aspire Health, a Nashville-based healthcare company providing in-home treatment across 25 U.S. states, experienced a cybersecurity breach initiated by a phishing attack. The phishing scheme successfully compromised Aspire’s internal email system, granting the attacker unauthorized access. Following this intrusion, the threat actor forwarded 124 internal emails to an external email account under their control. These emails contained confidential and proprietary business information alongside protected health information (PHI) belonging to patients. The breach remained undisclosed publicly until court records filed on September 25, 2018, revealed the incident, though the exact timeline of detection and internal response was not detailed in available records. The attacker’s identity and motives were not disclosed, and no evidence suggested broader network infiltration beyond the email compromise.

The exfiltrated data included sensitive patient health information governed by HIPAA regulations, though the specific number of affected individuals or types of PHI (e.g., medical records, identifiers) were not enumerated in court filings. Aspire Health’s disclosure emphasized the loss of both corporate data and patient information, indicating operational and compliance impacts. The company pursued legal action to address the breach, as evidenced by the federal court records, though no technical remediation steps (e.g., system hardening, phishing training) or patient notification processes were publicly described. The incident highlighted risks associated with email-based attacks targeting healthcare providers handling sensitive data across multiple jurisdictions. No additional consequences, such as regulatory penalties or secondary attacks linked to the breach, were reported in the available source material.

Sources

Sources available to members: 1 source.

CSIDB