McLeod Health said that they have handled a security incident involving emails that may have involved some of that information.
The contents of an email account that was accessed by an uninvited actor are currently being examined by McLeod.
The contents of the email account were automatically downloaded by the unauthorised actor, according to a thorough forensic assessment of the email environment.
In order to help prevent a repeat of the occurrence, they also claimed to have protected the account and changed the account settings throughout their workplace.
Additionally, they advised patients to routinely review the invoices they get from their medical professionals. We advise them to contact the provider right away if they notice any services they did not obtain.
TPRM report: https://scoringcyber.rankiteo.com/company/mcleod-health
"id": "mcl11284623",
"linkid": "mcleod-health",
"type": "Data Leak",
"date": "11/2020",
"severity": "50",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Healthcare',
'name': 'McLeod Health',
'type': 'Healthcare Provider'}],
'attack_vector': 'Email Account Compromise',
'data_breach': {'data_exfiltration': True,
'type_of_data_compromised': ['Patient Information']},
'description': 'McLeod Health experienced a security incident where an '
'unauthorized actor accessed an email account. The contents of '
'the email account were automatically downloaded by the '
'unauthorized actor, potentially compromising some patient '
'information. McLeod Health has secured the account and '
'advised patients to review their medical bills for any '
'unrecognized services.',
'impact': {'data_compromised': ['Patient Information'],
'systems_affected': ['Email Account']},
'initial_access_broker': {'entry_point': 'Email Account'},
'response': {'communication_strategy': ['Advised patients to review medical '
'bills and contact providers for '
'unrecognized services'],
'containment_measures': ['Secured the email account',
'Changed account settings across the '
'enterprise']},
'threat_actor': 'Unauthorized Actor',
'title': 'McLeod Health Email Account Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Weak email account security'}