Marquette County Medical Care Facility: Marquette County Medical Care Facility discloses data breach – DataBreaches.Net

Marquette County Medical Care Facility: Marquette County Medical Care Facility discloses data breach – DataBreaches.Net

Marquette County Medical Care Facility Hit by Business Email Compromise in March 2025

In March 2025, Marquette County Medical Care Facility (MCMCF), a 140-bed healthcare provider in Michigan, disclosed a business email compromise (BEC) incident affecting its Human Resources director’s Microsoft Office 365 account. The breach was detected on March 3, 2025, after contacts began receiving phishing emails from the compromised account.

The exposed data may have included names, Social Security numbers, dates of birth, protected health information (PHI), and bank details, though it remains unclear whether the incident impacted only employees or also extended to patient records. MCMCF operates a long-term care and rehabilitation facility, including a specialized unit for individuals with dementia.

While the facility’s press release did not mention free mitigation services for affected individuals, it established a dedicated helpline (1-833-998-7185) for inquiries, available Monday through Friday from 8:00 a.m. to 8:00 p.m. EST. The full scope of the breach and its impact on operations have not been detailed.

Source: https://databreaches.net/2025/06/24/marquette-county-medical-care-facility-discloses-data-breach/

Marquette County Medical Care Facility cybersecurity rating report: https://www.rankiteo.com/company/mcmcf

"id": "MCM1767852088",
"linkid": "mcmcf",
"type": "Breach",
"date": "6/2025",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Healthcare',
                        'location': 'Marquette County',
                        'name': 'Marquette County Medical Care Facility '
                                '(MCMCF)',
                        'size': '140-bed facility',
                        'type': 'Healthcare Facility'}],
 'attack_vector': 'Phishing',
 'customer_advisories': 'Dedicated toll-free helpline provided for affected '
                        'individuals',
 'data_breach': {'personally_identifiable_information': 'Names, social '
                                                        'security numbers, '
                                                        'dates of birth',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)',
                                              'Protected Health Information '
                                              '(PHI)',
                                              'Financial Information']},
 'date_detected': '2025-03-03',
 'date_publicly_disclosed': '2025-03',
 'description': 'Marquette County Medical Care Facility (MCMCF) discovered a '
                'business email compromise incident on March 3, 2025, when '
                'contacts of MCMCF’s Human Resources director began receiving '
                'phishing emails from her Microsoft Office 365 (O365) account. '
                'The incident involved unauthorized access to sensitive '
                'information including names, social security numbers, dates '
                'of birth, protected health information, and bank details.',
 'impact': {'data_compromised': 'Names, social security numbers, dates of '
                                'birth, protected health information, bank '
                                'details',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High',
            'systems_affected': 'Microsoft Office 365 (O365) account'},
 'initial_access_broker': {'entry_point': 'Compromised Microsoft Office 365 '
                                          'account'},
 'references': [{'source': 'MCMCF Press Release'}],
 'regulatory_compliance': {'regulations_violated': ['HIPAA']},
 'response': {'communication_strategy': 'Dedicated toll-free helpline '
                                        '(1-833-998-7185, Monday through '
                                        'Friday, 8:00 a.m. to 8:00 p.m. EST)'},
 'title': 'Marquette County Medical Care Facility Business Email Compromise '
          'Incident',
 'type': 'Business Email Compromise (BEC)',
 'vulnerability_exploited': 'Compromised Microsoft Office 365 account'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.