Vanderbilt Health: Vanderbilt Health says patient information may have been accessed in employee email breach

Vanderbilt Health: Vanderbilt Health says patient information may have been accessed in employee email breach

Vanderbilt Health Reports Potential Patient Data Exposure Following Phishing Attack

Vanderbilt Health disclosed that unauthorized access to an employee’s email account may have exposed sensitive patient information. On March 23, an employee fell victim to a phishing attack by clicking a malicious link, granting a cybercriminal access to the account. The breach was detected on March 27.

Potentially compromised data includes patient names, medical record numbers, visit dates, diagnosis or procedure details, and provider or facility names. However, officials confirmed that Social Security numbers and financial account information were not affected, and there is no evidence the data has been misused.

Vanderbilt Health emphasized its commitment to patient privacy, stating that while no misuse has been detected, the organization is taking steps to strengthen security measures. The incident did not impact the electronic medical record system, and affected patients are being notified. Complimentary credit monitoring is being offered as a precaution.

Source: https://fox17.com/news/local/vanderbilt-health-says-patient-information-may-have-been-accessed-in-employee-email-breach-sondra-hornsey-msed-chpc-chc-chief-privacy-officer

Vanderbilt Health TPRM report: https://www.rankiteo.com/company/vanderbilt-university-medical-center

"id": "van1784939082",
"linkid": "vanderbilt-university-medical-center",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Patients (number not specified)',
                        'industry': 'Healthcare',
                        'name': 'Vanderbilt Health',
                        'type': 'Healthcare Provider'}],
 'attack_vector': 'Malicious Link',
 'customer_advisories': 'Affected patients are being notified and offered '
                        'complimentary credit monitoring',
 'data_breach': {'data_exfiltration': 'No evidence of misuse',
                 'personally_identifiable_information': 'Names, medical record '
                                                        'numbers, '
                                                        'diagnosis/procedure '
                                                        'details',
                 'sensitivity_of_data': 'High (medical information)',
                 'type_of_data_compromised': 'Patient information'},
 'date_detected': '2024-03-27',
 'description': 'Vanderbilt Health disclosed that unauthorized access to an '
                'employee’s email account may have exposed sensitive patient '
                'information. An employee fell victim to a phishing attack by '
                'clicking a malicious link, granting a cybercriminal access to '
                'the account.',
 'impact': {'data_compromised': 'Patient names, medical record numbers, visit '
                                'dates, diagnosis or procedure details, '
                                'provider or facility names',
            'identity_theft_risk': 'Potential',
            'payment_information_risk': 'None (Social Security numbers and '
                                        'financial account information were '
                                        'not affected)',
            'systems_affected': 'Employee email account'},
 'initial_access_broker': {'entry_point': 'Phishing email (malicious link)'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'corrective_actions': 'Strengthening security '
                                                  'measures',
                            'root_causes': 'Employee clicked on a malicious '
                                           'link in a phishing email'},
 'references': [{'source': 'Vanderbilt Health Disclosure'}],
 'response': {'communication_strategy': 'Notifying affected patients, offering '
                                        'complimentary credit monitoring',
              'remediation_measures': 'Strengthening security measures'},
 'title': 'Vanderbilt Health Potential Patient Data Exposure Following '
          'Phishing Attack',
 'type': 'Phishing Attack',
 'vulnerability_exploited': 'Human Error (Phishing)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.