The Nova Scotia Health Authority suffered from a data breach incident that exposed 3,000 people personal health information.
The health authority says the breach was detected by its IT team after an employee’s email account was compromised due to a phishing attack.
It was found that the employee used her username and password on a false link sent to her email, allowing access to the employee’s email inbox.
The breach of information was related to surgical procedures scheduled or going to be scheduled at the Colchester East Hants Health Centre.
Source: https://globalnews.ca/news/5373338/nova-scotia-health-authority-privacy-breach/
TPRM report: https://scoringcyber.rankiteo.com/company/nsha
"id": "nov44925323",
"linkid": "nsha",
"type": "Breach",
"date": "06/2019",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 3000,
'industry': 'Healthcare',
'location': 'Nova Scotia',
'name': 'Nova Scotia Health Authority',
'type': 'Healthcare Provider'}],
'attack_vector': 'Phishing',
'data_breach': {'number_of_records_exposed': 3000,
'type_of_data_compromised': 'Personal health information'},
'description': 'The Nova Scotia Health Authority suffered from a data breach '
"incident that exposed 3,000 people's personal health "
'information. The breach was detected by the IT team after an '
'employee’s email account was compromised due to a phishing '
'attack. The employee used her username and password on a '
'false link sent to her email, allowing access to the '
'employee’s email inbox. The breach of information was related '
'to surgical procedures scheduled or going to be scheduled at '
'the Colchester East Hants Health Centre.',
'impact': {'data_compromised': ['Personal health information']},
'initial_access_broker': {'entry_point': 'Phishing email'},
'post_incident_analysis': {'root_causes': 'Phishing attack leading to '
'compromised email account'},
'title': 'Nova Scotia Health Authority Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Compromised email account'}