Corewell Health Data Breach Exposes Personal and Medical Data of 19,000 Patients
A data breach at Pinnacle Holdings, LTD a former healthcare consulting provider for Michigan-based Corewell Health has compromised the sensitive information of approximately 19,000 Corewell Health patients. The incident occurred on November 25, 2024, when Pinnacle Holdings detected a "network disruption" affecting certain systems.
During its investigation, the Colorado-based firm determined that an unauthorized individual may have accessed patient data. Corewell Health was notified of the breach in early 2024 and promptly launched a review to identify affected individuals. Exposed information includes names, phone numbers, Social Security numbers, driver’s license numbers, dates of birth, health insurance details, prescription information, and service dates.
Pinnacle Holdings stated it has since implemented additional safeguards to prevent future incidents and has begun notifying impacted individuals. As part of the response, affected patients are being offered free credit monitoring and identity protection services. The firm reported no evidence of fraudulent activity resulting from the breach.
Individuals seeking more information can contact Pinnacle Holdings at 866-686-2607.
Source: https://www.cbsnews.com/detroit/news/corewell-health-pinnacle-holdings-data-breach/
Pinnacle Healthcare Consulting cybersecurity rating report: https://www.rankiteo.com/company/pinnacle-healthcare-consulting-llc
Corewell Health cybersecurity rating report: https://www.rankiteo.com/company/corewell-health
"id": "PINCOR1774758354",
"linkid": "pinnacle-healthcare-consulting-llc, corewell-health",
"type": "Breach",
"date": "11/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '19,000',
'industry': 'Healthcare',
'location': 'Michigan, USA',
'name': 'Corewell Health',
'type': 'Healthcare Provider'},
{'industry': 'Healthcare Consulting',
'location': 'Colorado, USA',
'name': 'Pinnacle Holdings, LTD',
'type': 'Healthcare Consulting Provider'}],
'customer_advisories': 'Affected patients are being offered free credit '
'monitoring and identity protection services. Contact '
'Pinnacle Holdings at 866-686-2607 for more '
'information.',
'data_breach': {'number_of_records_exposed': '19,000',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Phone numbers',
'Social Security numbers',
'Driver’s license numbers',
'Dates of birth',
'Health insurance details',
'Prescription information',
'Service dates']},
'date_detected': '2024-11-25',
'description': 'A data breach at Pinnacle Holdings, LTD, a former healthcare '
'consulting provider for Michigan-based Corewell Health, has '
'compromised the sensitive information of approximately 19,000 '
'Corewell Health patients. The incident occurred when Pinnacle '
"Holdings detected a 'network disruption' affecting certain "
'systems. An unauthorized individual may have accessed patient '
'data, including names, phone numbers, Social Security '
'numbers, driver’s license numbers, dates of birth, health '
'insurance details, prescription information, and service '
'dates.',
'impact': {'data_compromised': 'Personal and medical data of 19,000 patients',
'identity_theft_risk': 'High'},
'investigation_status': 'Ongoing',
'references': [{'source': 'Incident Report'}],
'response': {'communication_strategy': 'Notifying impacted individuals and '
'offering free credit monitoring and '
'identity protection services',
'containment_measures': 'Additional safeguards implemented to '
'prevent future incidents'},
'title': 'Corewell Health Data Breach Exposes Personal and Medical Data of '
'19,000 Patients',
'type': 'Data Breach'}