Skip to content
NetarxImpact Database
Business Email CompromiseNo AI reportedConfirmed

UnityPoint Health phishing of executive-spoofed emails exposes 1.4 million patients

UnityPoint Health · Healthcare · United States · March 2018

Business impact
$2,800,000
Lost revenue, earnings impact, remediation cost, a settlement or damages sought. Not money stolen.
US$2.8 million class-action settlement to resolve litigation over the breach.
People or records affected
1,400,000
1.4M as reported

What happened

UnityPoint Health, an Iowa-based health system, disclosed in July 2018 that a phishing campaign had compromised multiple employee email accounts between 14 March and 3 April 2018, exposing data on approximately 1.4 million patients. It was the largest US health data breach reported that year. Investigators concluded the attackers were most likely trying to divert vendor or payroll payments rather than steal medical records.

How the deception worked

The phishing emails were crafted to appear to come from an executive inside UnityPoint Health, which gave them the internal legitimacy that gets messages read and links clicked. Staff who followed the links and entered their credentials handed over access to their mailboxes, and the attackers used those accounts for about three weeks. The financial motive shows in what they did next: they hunted for vendor invoices and payroll processes to redirect. The patient data exposure, which included medical, insurance, Social Security and in some cases payment card details, was collateral, simply whatever happened to be sitting in the compromised inboxes.

The control that would have caught it· our reading, not a claim from the sources

Multi-factor authentication on clinical staff email, and a policy against storing patient identifiers in mailboxes, would have limited both the access and the exposure.

Sources (2)

  1. 1.4 million patient records breached in UnityPoint Health phishing attack
    Healthcare IT News·healthcareitnews.comOpen ↗
  2. 1.4 Million Patients Warned About UnityPoint Health Phishing Attack
    HIPAA Journal·hipaajournal.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.