The medical records of 120 patients of the Chatham-Kent Health Alliance were accessed in a cyber security incident recently.
On investigating the incident it was discovered that two of its employees without an apparent valid reason to do so.
CKHA terminated both the employees and provided the other staff education with annual privacy training in addition to annual Hospital Information System training.
Source: https://chathamvoice.com/2022/03/30/120-patients-victims-of-ckha-privacy-breach/
TPRM report: https://scoringcyber.rankiteo.com/company/chatham-kent-health-alliance
"id": "cha0434522",
"linkid": "chatham-kent-health-alliance",
"type": "Breach",
"date": "03/2022",
"severity": "80",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 120,
'industry': 'Healthcare',
'name': 'Chatham-Kent Health Alliance',
'type': 'Healthcare Provider'}],
'attack_vector': 'Insider Threat',
'data_breach': {'number_of_records_exposed': 120,
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Medical Records'},
'description': 'The medical records of 120 patients of the Chatham-Kent '
'Health Alliance were accessed in a cyber security incident '
'recently. On investigating the incident it was discovered '
'that two of its employees without an apparent valid reason to '
'do so.',
'impact': {'data_compromised': 'Medical Records'},
'motivation': 'Unknown',
'response': {'remediation_measures': ['Terminated Employees',
'Provided Annual Privacy Training',
'Provided Annual Hospital Information '
'System Training']},
'threat_actor': ['Employee'],
'title': 'Unauthorized Access to Medical Records',
'type': 'Data Breach'}