The bundle of patients' confidential records from the West Suffolk Hospital in Bury St Edmunds was found by a member of the public at Trumpington Meadows near Cambridge.
The hospital list included the full names, dates of birth, medical history, and reason for admission of 12 patients.
It also outlined patients' health problems, including mental health conditions such as anxiety and depression.
The email featured the elderly patient's name, NHS number, date of birth, address, phone number, and the reason why they were due to have an operation.
Source: https://www.cambridge-news.co.uk/news/local-news/west-suffolk-hospital-apologises-after-17867278
TPRM report: https://scoringcyber.rankiteo.com/company/westsuffolknhs
"id": "wes2218231222",
"linkid": "westsuffolknhs",
"type": "Data Leak",
"date": "03/2020",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 12,
'industry': 'Healthcare',
'location': 'Bury St Edmunds',
'name': 'West Suffolk Hospital',
'type': 'Healthcare Facility'}],
'attack_vector': 'Physical Theft',
'data_breach': {'number_of_records_exposed': 12,
'personally_identifiable_information': ['Full names',
'Dates of birth',
'NHS number',
'Address',
'Phone number'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personal Information',
'Medical Information']},
'description': 'Confidential patient records from West Suffolk Hospital were '
'found by a member of the public at Trumpington Meadows near '
'Cambridge. The records included full names, dates of birth, '
'medical history, reasons for admission, and health problems '
"of 12 patients. An email also featured an elderly patient's "
'name, NHS number, date of birth, address, phone number, and '
'reason for their operation.',
'impact': {'data_compromised': ['Full names',
'Dates of birth',
'Medical history',
'Reasons for admission',
'Health problems',
'NHS number',
'Address',
'Phone number']},
'title': 'Data Breach at West Suffolk Hospital',
'type': 'Data Breach'}