CSIDB logo
Incident

Assurance Health System

Incident posture

Attack window
Apr 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-20 00:00

Linked entities

Victim
Assurance Health System
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Assurance Health System experienced unauthorized access to two employee email accounts, compromising sensitive patient data including names, contact details, Social Security and driver’s license numbers, medical histories, treatment information, diagnoses, prescriptions, and health insurance details. The breach affected 3,565 individuals across multiple facilities, prompting notifications and complimentary credit monitoring and identity protection services for those with exposed Social Security or driver’s license numbers. The organization implemented enhanced email security measures and monitoring following the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Assurance Health System, an Indianapolis-based provider of senior inpatient psychiatric care operating in central Indiana and Ohio, experienced a breach involving unauthorized access to two employee email accounts. Forensic investigations determined one account was compromised between April 8, 2022, and April 21, 2022, while the second account showed unauthorized access spanning from June 10, 2021, to March 8, 2022. The organization completed its review of the affected accounts on September 1, 2022, though the exact date of initial detection remains unspecified in available reports. Notification letters were dispatched to 3,565 affected individuals starting October 28, 2022. The breach impacted patients across three affiliated facilities: Assurance Health, Anew Health, and Brightwell Behavioral Health.

The compromised email accounts contained extensive protected health information including patient names, contact details, Social Security numbers, driver's license numbers, dates of birth, medical record and account numbers, treatment dates and locations, medical histories, diagnosis details, provider names, prescription information, and health insurance data. Individuals whose Social Security numbers or driver's license numbers were exposed received offers for complimentary credit monitoring and identity protection services. Assurance Health System implemented additional technical safeguards and enhanced monitoring of its email environment following the incident. The organization did not specify whether the breach originated from phishing attacks or other vectors, though it confirmed no broader system compromise beyond the two email accounts. Forensic analysis established the precise timelines of unauthorized access but did not identify the threat actor or confirm any actual misuse of the exposed data.

Sources

Sources available to members: 1 source.

CSIDB