Menu
Browse

Cyber Incident Victim: University of Louisville

Date:

Sep 2018

Location:

United States of America

Summary

A data breach at the University of Louisville compromised personal information of nearly 250 faculty, staff, and retirees enrolled in the "Get Healthy Now" wellness program, operated by Health Fitness. Exposed data included employee names, identification numbers, physicians' names, limited medical details, and program coaching forms, though no financial or Social Security information was involved. The institution confirmed unauthorized access occurred through the third-party program and notified affected individuals after verification, offering one year of complimentary credit monitoring. While no evidence of misuse was found, the incident impacted multiple organizations beyond the university.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On September 11, 2018, the University of Louisville notified faculty and staff via mass email about a data breach impacting participants in its "Get Healthy Now" employee wellness program. The incident affected 247 current employees and retirees who had enrolled in the program between 2007 and 2014. Unauthorized actors accessed personal information including employee names, university-issued employee identification numbers, and physician names. In one isolated case, a limited amount of medical information was compromised. Program-specific documents related to health coaching sessions were also exfiltrated. The university clarified that no Social Security numbers or financial data were exposed in the breach. University officials emphasized they found no evidence suggesting the stolen information had been used for fraudulent purposes following forensic analysis. The breach originated from systems managed by Health Fitness, the third-party vendor administering the Get Healthy Now program, and impacted multiple client institutions beyond the University of Louisville.

Cyber Incident Image

The university first received notification of the security incident from Health Fitness on August 24, 2018, initiating an 18-day investigation period to verify affected individuals. By September 11, all 247 impacted persons had been directly contacted through individualized communications. Health Fitness offered affected individuals one year of complimentary credit monitoring services as remediation. The university directed concerned faculty and staff to contact the Get Healthy Now program office during standard business hours for additional assistance. No disruptions to university operations or academic functions were reported as a consequence of the breach. The incident exclusively compromised historical program participation records without affecting active employee databases or university information systems.

Sources
Sources available to members
1 source