Huntington Hospital in New York suspected unauthorized access to patient records by an employee and suspended the employee.
The former employee accessed Social Security numbers, insurance information, credit card numbers or other payment-related information. The patient information accessed by the former employee may have included demographic-type information such as name, date of birth, telephone number, address, internal account number and medical record number; and clinical information such as diagnoses, medications, laboratory results, course of treatment, the names of health care providers, and/or other treatment-related information of about 13,000 patients.
TPRM report: https://scoringcyber.rankiteo.com/company/huntington-health
"id": "hun233721123",
"linkid": "huntington-health",
"type": "Data Leak",
"date": "11/2021",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 13000,
'industry': 'Healthcare',
'location': 'New York',
'name': 'Huntington Hospital',
'type': 'Hospital'}],
'attack_vector': 'Insider Threat',
'data_breach': {'number_of_records_exposed': 13000,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Social Security numbers',
'Insurance information',
'Credit card numbers',
'Payment-related information',
'Demographic information',
'Clinical information']},
'description': 'Huntington Hospital in New York suspected unauthorized access '
'to patient records by an employee and suspended the employee. '
'The former employee accessed Social Security numbers, '
'insurance information, credit card numbers or other '
'payment-related information. The patient information accessed '
'by the former employee may have included demographic-type '
'information such as name, date of birth, telephone number, '
'address, internal account number and medical record number; '
'and clinical information such as diagnoses, medications, '
'laboratory results, course of treatment, the names of health '
'care providers, and/or other treatment-related information of '
'about 13,000 patients.',
'impact': {'data_compromised': ['Social Security numbers',
'Insurance information',
'Credit card numbers',
'Payment-related information',
'Demographic information',
'Clinical information']},
'threat_actor': 'Former Employee',
'title': 'Unauthorized Access to Patient Records at Huntington Hospital',
'type': 'Data Breach'}