The Vermont Office of the Attorney General disclosed a data breach at McKenzie County Healthcare Systems on April 10, 2024. The incident stemmed from an unauthorized actor accessing an employee’s email account between October 2 and October 4, 2023. While the exact scope remains unclear, the breach exposed personal information, including names, of affected individuals. The compromised email account likely contained sensitive data, though the full extent of the exposure such as whether medical records, financial details, or other personally identifiable information (PII) were accessed has not been specified. Healthcare breaches of this nature pose risks of identity theft, phishing attacks, or fraud, particularly if additional details (e.g., Social Security numbers, treatment histories) were involved. The delay in public disclosure (over six months) may further complicate mitigation efforts for impacted parties. As a healthcare provider, the organization is subject to HIPAA regulations, and the breach underscores vulnerabilities in email security protocols, potentially tied to phishing or credential theft.
TPRM report: https://www.rankiteo.com/company/mckenzie-health
"id": "mck726082025",
"linkid": "mckenzie-health",
"type": "Breach",
"date": "10/2023",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'Unknown',
'industry': 'Healthcare',
'name': 'McKenzie County Healthcare Systems',
'type': 'Healthcare Provider'}],
'attack_vector': 'Compromised Email Account',
'data_breach': {'number_of_records_exposed': 'Unknown',
'personally_identifiable_information': True,
'sensitivity_of_data': 'Moderate',
'type_of_data_compromised': ['Personal Information (Names)']},
'date_publicly_disclosed': '2024-04-10',
'description': 'The Vermont Office of the Attorney General reported a data '
'breach involving McKenzie County Healthcare Systems on April '
'10, 2024. The breach occurred when an unauthorized actor '
'gained access to an employee email account between October 2, '
'2023, to October 4, 2023, potentially affecting personal '
'information, including names, of unknown individuals.',
'impact': {'data_compromised': ['Names'],
'identity_theft_risk': 'Potential',
'systems_affected': ['Employee Email Account']},
'initial_access_broker': {'entry_point': 'Employee Email Account'},
'references': [{'date_accessed': '2024-04-10',
'source': 'Vermont Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': ['Vermont Office of the '
'Attorney General']},
'threat_actor': 'Unauthorized Actor',
'title': 'McKenzie County Healthcare Systems Data Breach',
'type': 'Data Breach'}