Chicago’s Northwestern Memorial HealthCare became a victim of Elekta’s recent data breach.
It exposed oncology patients’ protected health information (PHI) at nine Illinois hospitals.
An unauthorized individual gained access to its systems between April 2, 2021, and April 20, 2021, and, acquired a copy of the database that stores some oncology patient information.
The information compromised included patient names, dates of birth, Social Security numbers, health insurance information, medical record numbers, and clinical information related to cancer treatment, such as medical histories, physician names, dates of service, treatment plans, diagnoses, and/or prescription information. Financial account and payment card information were not involved.
TPRM report: https://scoringcyber.rankiteo.com/company/northwestern-medicine
"id": "nor21519123",
"linkid": "northwestern-medicine",
"type": "Data Leak",
"date": "04/2021",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'Chicago, Illinois',
'name': 'Northwestern Memorial HealthCare',
'type': 'Healthcare Provider'}],
'attack_vector': 'Unauthorized Access',
'data_breach': {'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Patient Names',
'Dates of Birth',
'Social Security Numbers',
'Health Insurance Information',
'Medical Record Numbers',
'Clinical Information related to '
'Cancer Treatment']},
'date_detected': 'April 20, 2021',
'description': 'Chicago’s Northwestern Memorial HealthCare became a victim of '
'Elekta’s recent data breach, exposing oncology patients’ '
'protected health information (PHI) at nine Illinois '
'hospitals. An unauthorized individual gained access to its '
'systems between April 2, 2021, and April 20, 2021, and '
'acquired a copy of the database that stores some oncology '
'patient information. The compromised information included '
'patient names, dates of birth, Social Security numbers, '
'health insurance information, medical record numbers, and '
'clinical information related to cancer treatment, such as '
'medical histories, physician names, dates of service, '
'treatment plans, diagnoses, and/or prescription information. '
'Financial account and payment card information were not '
'involved.',
'impact': {'data_compromised': ['Patient Names',
'Dates of Birth',
'Social Security Numbers',
'Health Insurance Information',
'Medical Record Numbers',
'Clinical Information related to Cancer '
'Treatment']},
'threat_actor': 'Unauthorized Individual',
'title': 'Data Breach at Northwestern Memorial HealthCare',
'type': 'Data Breach'}