Salinas Valley Memorial Healthcare System in California suffered a data breach incident after unauthorized individuals gained access to the email accounts of four employees and a contractor following responses to phishing emails.
The attackers accessed emails containing sensitive patient information including names, hospital account numbers, medical record numbers, dates of service, and other information.
Although prompt action was taken to secure its email environment, legal action was taken against Salinas Valley by a patient affected by the data breach.
Salinas Valley Memorial Healthcare System had to agreed to settle a class action lawsuit for $340,000 to resolve claims from patient.
TPRM report: https://scoringcyber.rankiteo.com/company/salinas-valley-memorial-healthcare-system
"id": "sal232910822",
"linkid": "salinas-valley-memorial-healthcare-system",
"type": "Ransomware",
"date": "04/2020",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'California',
'name': 'Salinas Valley Memorial Healthcare System',
'type': 'Healthcare Provider'}],
'attack_vector': 'Phishing',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Hospital account numbers',
'Medical record numbers',
'Dates of service']},
'description': 'Salinas Valley Memorial Healthcare System in California '
'suffered a data breach incident after unauthorized '
'individuals gained access to the email accounts of four '
'employees and a contractor following responses to phishing '
'emails. The attackers accessed emails containing sensitive '
'patient information including names, hospital account '
'numbers, medical record numbers, dates of service, and other '
'information. Although prompt action was taken to secure its '
'email environment, legal action was taken against Salinas '
'Valley by a patient affected by the data breach. Salinas '
'Valley Memorial Healthcare System had to agreed to settle a '
'class action lawsuit for $340,000 to resolve claims from '
'patient.',
'impact': {'data_compromised': ['Names',
'Hospital account numbers',
'Medical record numbers',
'Dates of service'],
'financial_loss': '$340,000',
'legal_liabilities': ['Class action lawsuit'],
'systems_affected': ['Email accounts']},
'initial_access_broker': {'entry_point': 'Phishing emails'},
'post_incident_analysis': {'root_causes': 'Phishing emails'},
'regulatory_compliance': {'legal_actions': ['Class action lawsuit']},
'response': {'containment_measures': ['Secured email environment']},
'title': 'Data Breach at Salinas Valley Memorial Healthcare System',
'type': 'Data Breach'}