Medical College of Wisconsin Phishing Attack May Affect Almost 10,500 People

by | Nov 27, 2017

A phishing attack at the Medical College of Wisconsin has lead to the exposure of approximately 9,500 patients’ protected health information. The hackers gained access to the email accounts of staff member, which included a range of private information regarding patients and some faculty employees.

The sort of information in the accessed email accounts included names, addresses, medical record numbers, birth dates, health insurance details, medical histories, treatment details, surgical information, and dates of service. A very limited number of individuals also had their Social Security numbers and bank account information exposed.

The incident occurred over week of July 21-28 2017 when spear phishing emails were broadcast to specific people at the Medical College of Wisconsin. Answering to those emails lead to the attackers gaining access to email login details.

The educational institution contracted in a computer forensics firm to conduct an investigation into the phishing campaign, and while that investigation found that access to the email accounts was gained by unauthorized individuals, it was not possible to rule whether emails containing protected health information had been accessed or seen, or if any sensitive information was taken. Since the cyberattack happened, no reports of illegal use of patient information have been received.

To safeguard individuals from identity theft and fraud, credit monitoring and identity theft restoration services have been offered to breach victims free of charge, but just to those people whose Social Security numbers were taken.

Medical College of Wisconsin remarked that along with some faculty staff and Medical College of Wisconsin patients, some individuals who were provided with treatment at Children’s Hospital of Wisconsin and Froedtert Health have also been harmed by the breach.

The latest Medical College of Wisconsin phishing attack comes roughly 10 months after a similar attack lead to the exposure of 3,200 patients’ protected health information by unauthorized people.

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

COMPREHENSIVE HIPAA TRAINING

Ryan Coyne

Ryan Coyne is a results-driven leader in the healthcare compliance industry, specializing in regulatory compliance, compliance training, and assisting healthcare organizations and business associates in achieving and maintaining compliance. With a deep knowledge of healthcare regulations and a keen understanding of the challenges faced by the industry, Ryan has developed a reputation as a trusted advisor and advocate for ethical and compliant practices in healthcare. Ryan has successfully advised and guided numerous healthcare organizations, business associates, and healthcare professionals on achieving and maintaining compliance with regulatory training requirements. Ryan's professional focus is using his in-depth expertise and leading a world class team of subject matter experts at ComplianceJunction in regulatory compliance to help organisations navigate the complex landscape of ensuring staff adhere to healthcare regulations. You can connect with Ryan via LinkedIn and follow on Twitter

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

Comprehensive HIPAA Training

Used in 1000+ Healthcare Organizations and 100+ Universities

    Full Course - Immediate Access

    Privacy Policy