Henry Mayo Newhall Hospital in Santa Clarita, CA fired several employees for compromising the medical records of the Saugus High School shooter.
Hospital staff is only permitted to access the medical records of patients with whom they have a treatment relationship or if there is an otherwise legitimate business relationship for accessing the records.
On November 14, 2009, a student of Saugus High School shot five students, killing two before turning the pistol on himself.
The shooter was taken to Henry Mayo Newhall Hospital where he died the following day.
Several employees at the hospital viewed the medical records of the shooter without any legitimate business purpose for doing so.
TPRM report: https://scoringcyber.rankiteo.com/company/henry-mayo-newhall-memorial-hospital
"id": "hen2212231222",
"linkid": "henry-mayo-newhall-memorial-hospital",
"type": "Data Leak",
"date": "03/2020",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'Santa Clarita, CA',
'name': 'Henry Mayo Newhall Hospital',
'type': 'Healthcare Provider'}],
'attack_vector': 'Unauthorized Access',
'data_breach': {'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Medical Records'},
'description': 'Henry Mayo Newhall Hospital in Santa Clarita, CA fired '
'several employees for compromising the medical records of the '
'Saugus High School shooter. Hospital staff is only permitted '
'to access the medical records of patients with whom they have '
'a treatment relationship or if there is an otherwise '
'legitimate business relationship for accessing the records. '
'On November 14, 2009, a student of Saugus High School shot '
'five students, killing two before turning the pistol on '
'himself. The shooter was taken to Henry Mayo Newhall Hospital '
'where he died the following day. Several employees at the '
'hospital viewed the medical records of the shooter without '
'any legitimate business purpose for doing so.',
'impact': {'data_compromised': ['Medical Records']},
'motivation': 'Unauthorized Curiosity',
'threat_actor': 'Internal Employees',
'title': 'Unauthorized Access to Medical Records at Henry Mayo Newhall '
'Hospital',
'type': 'Data Breach',
'vulnerability_exploited': 'Insider Threat'}