Menu
Browse

Cyber Incident Victim: Bon Secours St. Francis Health System

Date:

Jan 2019

Location:

United States of America

Summary

Unauthorized access to systems at Milestone Family Medicine, a practice affiliated with Bon Secours St. Francis Health System, potentially compromised patient information including names, dates of birth, Social Security numbers, addresses, health insurance details, and treatment-related data. The organization secured affected systems, initiated an investigation with third-party forensic assistance, and notified impacted individuals, offering complimentary credit monitoring and identity protection services for those whose Social Security numbers were exposed. While no evidence of data misuse was found, the health system implemented enhanced technology management and security oversight measures to prevent future incidents.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 3 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On January 4, 2019, Bon Secours St. Francis Health System discovered unauthorized access to systems at Milestone Family Medicine, a Greenville-based medical practice previously staffed by physicians employed through St. Francis Physician Services. The organization immediately secured the compromised account and initiated an investigation with assistance from a third-party forensic firm. Analysis revealed that patient information stored on one of the practice's servers was potentially exposed during the breach. The affected data included full names, dates of birth, Social Security numbers, physical addresses, health insurance details, and clinical information related to care received at Milestone Family Medicine. While the investigation confirmed data accessibility, no evidence emerged indicating actual misuse of patient information.

Cyber Incident Image

Bon Secours St. Francis began mailing notification letters to affected patients following the forensic review. The organization offered complimentary credit monitoring and identity protection services specifically to individuals whose Social Security numbers were exposed. Patients were advised to review healthcare statements for unrecognized charges and contact providers if discrepancies appeared. A dedicated call center (1-877-239-1255) operated weekdays from 9 a.m. to 9 p.m. Eastern Time to address patient inquiries. In response to the incident, Bon Secours St. Francis announced plans to enhance technology management protocols and strengthen information security risk oversight measures to prevent future breaches. The health system acknowledged the concern caused by the event but reiterated its commitment to patient privacy protections throughout its notification statement.

Sources
Sources available to members
1 source