Menu
Browse

Cyber Incident Victim: Brigham and Women's Hospital

Date:

Nov 2015

Location:

United States of America

Summary

An unauthorized party compromised an employee's email credentials at Brigham and Women’s Hospital and its Faulkner Hospital affiliate, accessing the account and potentially exposing patient information including names, dates of birth, medical record numbers, diagnoses, treatment details, and service dates. The breach did not involve financial data, insurance information, or the primary electronic medical records system. Following discovery, the organization secured the account, initiated an investigation with forensic experts, and notified approximately 1,009 affected individuals while establishing a dedicated call center for inquiries. Security enhancements were implemented, including technical safeguards and workforce re-education to prevent future incidents, with no evidence of misuse identified at the time of reporting.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 13, 2015, Brigham and Women’s Hospital and Brigham and Women’s Faulkner Hospitals discovered an unauthorized party had obtained the network credentials of one employee and used them to access that individual’s email account. The hospital secured the compromised account immediately upon detection and initiated an internal investigation, supplemented by support from an expert computer forensic firm. A comprehensive review of the email account determined that emails contained sensitive patient information for a limited number of individuals, including full names, dates of birth, medical record numbers, provider names, dates of service, and clinical details such as diagnoses and treatments. The investigation confirmed the breach did not involve health insurance numbers, financial data, or account information. The hospital emphasized the incident did not impact all patients or the electronic medical records system, limiting exposure to discrete information within the single email account. No evidence of misuse of the exposed patient data was identified during the investigation.

Cyber Incident Image

Brigham and Women’s began mailing notification letters to affected individuals on January 11, 2016, advising those who did not receive a letter by January 26 to contact a dedicated call center operational on weekdays. The hospital reported the incident to the U.S. Department of Health and Human Services on January 11, 2016, disclosing 1,009 affected patients. In response to the breach, the institution reinforced technical safeguards related to network credentials and conducted re-education initiatives for workforce members to prevent recurrence. The hospital reiterated its commitment to information security but did not disclose specific technical or procedural changes implemented beyond these general measures. The forensic review and containment efforts focused exclusively on the compromised email account, with no broader system compromise identified.

Sources
Sources available to members
1 source