Kingman Regional Medical Center reported a “security incident” on its website, which was shut down on April 8.
The hospital established that the configuration of the website made it possible for unauthorized persons to view some information entered into the website by KRMC customers.
This incident did not impact all KRMC customers, but affected 1,100 individuals who used the Request an Appointment feature on the website.
The exposed information includes customers’ names, dates of birth, and information related to their medical condition.
Source: https://kdminer.com/news/2019/jun/08/krmc-website-shut-down-april-possible-security-bre/
TPRM report: https://scoringcyber.rankiteo.com/company/kingman-regional-medical-center
"id": "kin34625323",
"linkid": "kingman-regional-medical-center",
"type": "Data Leak",
"date": "04/2019",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': 1100,
'industry': 'Healthcare',
'name': 'Kingman Regional Medical Center',
'type': 'Healthcare'}],
'attack_vector': 'Website Configuration Vulnerability',
'data_breach': {'number_of_records_exposed': 1100,
'personally_identifiable_information': ['Names',
'Dates of Birth'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information',
'Medical Information']},
'date_publicly_disclosed': '2023-04-08',
'description': 'Kingman Regional Medical Center reported a security incident '
'on its website, which was shut down on April 8. The '
'configuration of the website allowed unauthorized persons to '
'view some information entered by KRMC customers. This '
'incident affected 1,100 individuals who used the Request an '
'Appointment feature on the website. The exposed information '
'includes customers’ names, dates of birth, and information '
'related to their medical condition.',
'impact': {'data_compromised': ['Names',
'Dates of Birth',
'Medical Condition Information'],
'systems_affected': ['Website']},
'post_incident_analysis': {'root_causes': 'Improper configuration of the '
'website'},
'response': {'containment_measures': ['Website shut down']},
'title': 'Kingman Regional Medical Center Security Incident',
'type': 'Data Breach',
'vulnerability_exploited': 'Improper configuration of the website'}