Uconn Health suffered from a data breach incident after an unauthorized third party accessed employee email accounts, potentially breaching the privacy of 326,000 patients and others.
The information compromised includes details such as names, dates of birth, addresses, and billing and appointment information.
UConn said it can’t be certain if the unauthorized party viewed or acquired any of the private information.
UConn Health said it has sent letters to potentially impacted individuals and also offered free identity theft protection services to the 1,500 whose social security numbers could have been exposed.
TPRM report: https://scoringcyber.rankiteo.com/company/uconnhealth
"id": "uco43216223",
"linkid": "uconnhealth",
"type": "Breach",
"date": "02/2019",
"severity": "50",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 326000,
'industry': 'Healthcare',
'name': 'UConn Health',
'type': 'Healthcare Provider'}],
'attack_vector': 'Email Account Compromise',
'data_breach': {'number_of_records_exposed': 326000,
'personally_identifiable_information': ['social security '
'numbers'],
'type_of_data_compromised': ['names',
'dates of birth',
'addresses',
'billing information',
'appointment information']},
'description': 'UConn Health suffered from a data breach incident after an '
'unauthorized third party accessed employee email accounts, '
'potentially breaching the privacy of 326,000 patients and '
'others.',
'impact': {'data_compromised': ['names',
'dates of birth',
'addresses',
'billing information',
'appointment information'],
'identity_theft_risk': ['1,500 individuals with potentially '
'exposed social security numbers']},
'initial_access_broker': {'entry_point': 'Email Account Compromise'},
'response': {'communication_strategy': ['Sent letters to potentially impacted '
'individuals',
'Offered free identity theft '
'protection services to 1,500 '
'individuals']},
'threat_actor': 'Unauthorized third party',
'title': 'UConn Health Data Breach',
'type': 'Data Breach'}