Almost 7,000 patients were informed by Alberta Health Services that a doctor's Gmail account had been stolen, exposing their personal health information.
The doctor working at the Richmond Road Diagnostic Centre in Calgary improperly used a private account to transmit health information
While this privacy breach was unintentional and was deeply regretted by the physician, that does not in any way diminish the seriousness of the matter.
There was no evidence to suggest that affected patients' information has been accessed by the hacker, the agency says.
Source: https://www.cbc.ca/news/canada/calgary/ahs-privacy-breach-email-richmond-diagnostic-centre-1.5256031
TPRM report: https://scoringcyber.rankiteo.com/company/alberta-health-services
"id": "alb11183423",
"linkid": "alberta-health-services",
"type": "Data Leak",
"date": "08/2019",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '7,000 patients',
'industry': 'Healthcare',
'location': 'Calgary, Alberta',
'name': 'Alberta Health Services',
'type': 'Healthcare Provider'}],
'attack_vector': 'Phishing',
'data_breach': {'number_of_records_exposed': '7,000',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personal health information'},
'description': 'Almost 7,000 patients were informed by Alberta Health '
"Services that a doctor's Gmail account had been stolen, "
'exposing their personal health information. The doctor '
'working at the Richmond Road Diagnostic Centre in Calgary '
'improperly used a private account to transmit health '
'information. While this privacy breach was unintentional and '
'was deeply regretted by the physician, that does not in any '
'way diminish the seriousness of the matter. There was no '
"evidence to suggest that affected patients' information has "
'been accessed by the hacker, the agency says.',
'impact': {'data_compromised': 'Personal health information'},
'title': 'Alberta Health Services Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Improper use of private email account'}