What happened
Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.
How the deception worked
The attacker already held the employee's password and needed only the second factor, so they triggered an authentication push to the employee's device. The employee approved it. That is the whole attack: no link was clicked and no page was visited, only a notification approved out of reflex or annoyance, which is why push-based MFA fails in a way that hardware keys cannot. With the account open, the attacker had ordinary access to a clinician's mailbox, where routine correspondence carries medical record numbers, diagnoses and treatment details for tens of thousands of patients. Michigan Medicine disabled the account, blocked the attacker's IP address and forced password resets.
The control that would have caught it· our reading, not a claim from the sources
Number matching or, better, phishing-resistant hardware authenticators remove the ability to grant access by approving a prompt, and staff need a clear instruction to report unexpected prompts.
Sources (2)
- Michigan Medicine notifies patients of health information breachMichigan Medicine·michiganmedicine.orgOpen ↗
- Michigan Medicine email breach exposes patient informationBecker's Hospital Review·beckershospitalreview.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.