Vanderbilt Health: Vanderbilt Health notifies patients of past data security breach

Vanderbilt Health: Vanderbilt Health notifies patients of past data security breach

Vanderbilt Health Discloses Data Breach Affecting Patient Information

Vanderbilt Health has notified a limited number of patients about a data security breach that occurred in March 2024. The incident stemmed from an employee clicking a malicious link, granting an unauthorized individual access to an email account on March 23.

An investigation revealed that the intruder accessed documents containing patient information, including names, medical record numbers, admission/discharge dates, diagnosis or procedure details, and provider or facility names. While no Social Security numbers or financial data were exposed, and there is no evidence of misuse, Vanderbilt Health confirmed the breach on March 27 after detecting the unauthorized access.

The compromised account was secured, and the breach did not impact Vanderbilt Health’s electronic medical record system. The exact number of affected patients remains undisclosed.

In response, Vanderbilt Health is strengthening email and digital security measures and expanding cybersecurity awareness training for staff. Patients with concerns may contact the Vanderbilt Health Privacy Office.

Source: https://www.tennessean.com/story/news/local/2026/07/25/vanderbilt-health-patients-data-security-breach/91049864007/

Vanderbilt University Medical Center cybersecurity rating report: https://www.rankiteo.com/company/vanderbilt-university-medical-center

"id": "VAN1785018273",
"linkid": "vanderbilt-university-medical-center",
"type": "Breach",
"date": "3/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare',
                        'name': 'Vanderbilt Health',
                        'type': 'Healthcare Provider'}],
 'attack_vector': 'Phishing (Malicious Link)',
 'customer_advisories': 'Patients with concerns may contact the Vanderbilt '
                        'Health Privacy Office',
 'data_breach': {'personally_identifiable_information': 'Yes (Names, Medical '
                                                        'Record Numbers)',
                 'sensitivity_of_data': 'High (Patient Health Information)',
                 'type_of_data_compromised': ['Names',
                                              'Medical record numbers',
                                              'Admission/discharge dates',
                                              'Diagnosis/procedure details',
                                              'Provider/facility names']},
 'date_detected': '2024-03-23',
 'date_publicly_disclosed': '2024-03-27',
 'description': 'Vanderbilt Health disclosed a data security breach stemming '
                'from an employee clicking a malicious link, granting '
                'unauthorized access to an email account. The intruder '
                'accessed documents containing patient information, including '
                'names, medical record numbers, admission/discharge dates, '
                'diagnosis or procedure details, and provider or facility '
                'names.',
 'impact': {'data_compromised': 'Patient information (names, medical record '
                                'numbers, admission/discharge dates, '
                                'diagnosis/procedure details, '
                                'provider/facility names)',
            'payment_information_risk': 'None (No financial data exposed)',
            'systems_affected': 'Email account'},
 'initial_access_broker': {'entry_point': 'Phishing email (Malicious link)'},
 'investigation_status': 'Completed (No evidence of misuse found)',
 'post_incident_analysis': {'corrective_actions': 'Strengthened email and '
                                                  'digital security measures, '
                                                  'expanded cybersecurity '
                                                  'awareness training',
                            'root_causes': 'Employee clicked a malicious link, '
                                           'granting unauthorized access to an '
                                           'email account'},
 'references': [{'source': 'Vanderbilt Health Disclosure'}],
 'response': {'communication_strategy': 'Notified affected patients, provided '
                                        'contact for concerns',
              'containment_measures': 'Compromised account was secured',
              'remediation_measures': 'Strengthening email and digital '
                                      'security measures, expanding '
                                      'cybersecurity awareness training for '
                                      'staff'},
 'title': 'Vanderbilt Health Data Breach Affecting Patient Information',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Human Error (Employee Clicked Malicious Link)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.