What happened
New Mexico's largest health system, Presbyterian Healthcare Services, disclosed in August 2019 that a phishing attack had given attackers access to employee email accounts beginning around 9 May 2019, detected on 6 June. The compromised mailboxes held the information of approximately 183,000 patients and health plan members, including names, dates of birth, Social Security numbers and clinical and insurance details. Presbyterian later settled class-action litigation over the incident.
How the deception worked
Attackers sent phishing emails to Presbyterian staff that led to a page requesting their work credentials. Staff who entered their username and password gave the attackers direct log-in access to the organisation's email system, with no malware involved and nothing unusual for endpoint tools to detect. Access ran for about four weeks before it was found. As with most healthcare mailbox compromises, the exposure came from the ordinary contents of clinical and administrative inboxes, which routinely carry patient identifiers, diagnoses, insurance data and Social Security numbers in message bodies and attachments.
The control that would have caught it· our reading, not a claim from the sources
Multi-factor authentication on webmail is the single control that turns a harvested healthcare password into a dead end.
Sources (2)
- Phishing Attack on Presbyterian Healthcare Services Exposed PHI of 183,000 PatientsHIPAA Journal·hipaajournal.comOpen ↗
- Presbyterian Healthcare phishing scam hits 183K patient recordsHealthcare IT News·healthcareitnews.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.