CSIDB logo
Incident

University of Chicago Medical Center

Incident posture

Attack window
Mar 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-20 00:00

Linked entities

Victim
University of Chicago Medical Center
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

UChicago Medicine experienced unauthorized access to several employee email accounts over a period, compromising sensitive patient information including names, Social Security numbers, health records, insurance details, and driver's license numbers. The breach impacted 2,568 individuals, leading the organization to implement enhanced authentication protocols, strengthen threat monitoring, and provide additional employee training on email security while notifying affected parties.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 24, 2022, the University of Chicago Medical Center (UCMC) identified unauthorized access to several employee email accounts. The intrusion persisted until March 31, 2022, during which an external actor maintained illicit access to these accounts. The compromised email systems contained sensitive patient information, including full names, Social Security numbers, medical details, historical Medicare beneficiary identification numbers, health insurance policy identifiers, and driver’s license numbers. UCMC initiated an investigation upon discovery and confirmed the exposure of protected health information (PHI) and personally identifiable information (PII). The organization did not specify the exact number of breached email accounts or the method of initial compromise but acknowledged the attacker’s sustained access over the seven-day period.

The breach impacted 2,568 patients, as subsequently reported to the U.S. Department of Health and Human Services (HHS) via its public data breach portal. UCMC began notifying affected individuals after concluding its internal review, detailing the types of exposed data in communications to patients. In response, the institution implemented enhanced user authentication protocols and expanded its threat monitoring and detection capabilities. It also initiated mandatory employee training programs focused on email security best practices. UCMC mailed formal notification letters to all impacted patients, though no ransomware involvement, financial demands, or data misuse claims were disclosed in available reports. The incident remained confined to email account compromises without evidence of broader network infiltration or system-wide data exfiltration.

Sources

Sources available to members: 1 source.

CSIDB