According to Roper St. Francis Hospital officials, 6,000 patients were impacted by an incident in which a worker's email was accessed by someone else without their consent, giving them access to personal medical records and data.
The exposed data includes names, birth dates, access to extensive medical records, and in a small number of cases, Social Security numbers and/or health insurance information.
RSFH will provide free credit monitoring and identity protection services for patients whose Social Security numbers have been accessed.
RSFH is strengthening its email security and giving personnel ongoing training on email security to assist avoid this from happening again.
TPRM report: https://scoringcyber.rankiteo.com/company/roperstfrancishealthcare
"id": "rop1419623",
"linkid": "roperstfrancishealthcare",
"type": "Data Leak",
"date": "09/2020",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 6000,
'industry': 'Healthcare',
'name': 'Roper St. Francis Hospital',
'type': 'Healthcare'}],
'attack_vector': 'Email Account Compromise',
'data_breach': {'number_of_records_exposed': 6000,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personal Information',
'Medical Records',
'Social Security numbers',
'Health Insurance Information']},
'description': "An unauthorized access to a worker's email resulted in the "
'exposure of personal medical records and data of 6,000 '
'patients.',
'impact': {'data_compromised': ['names',
'birth dates',
'medical records',
'Social Security numbers',
'health insurance information']},
'initial_access_broker': {'entry_point': 'Email'},
'post_incident_analysis': {'corrective_actions': ['Strengthening email '
'security',
'Ongoing training on email '
'security']},
'references': [{'source': 'Roper St. Francis Hospital officials'}],
'response': {'remediation_measures': ['Strengthening email security',
'Ongoing training on email security']},
'title': 'Roper St. Francis Hospital Data Breach',
'type': 'Data Breach'}