Skip to content
NetarxImpact Database
Credential Phishing PortalNo AI reportedConfirmed

Monongalia Health System email phishing breach affects 4,895 patients

Monongalia Health System (Mon Health) · Healthcare · United States · March 3, 2025

People or records affected
4,895
4.9K as reported

What happened

West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.

How the deception worked

Employees were sent phishing messages that imitated routine internal or Microsoft 365 notifications and were induced to enter their work credentials on a lookalike sign-in page. Hospital email is a high-yield target because clinical and billing staff exchange large volumes of patient-identifying correspondence with outside parties, so an unexpected message about a shared document or account issue does not stand out. With the harvested credentials the attacker signed in as the employee and had access to the full mailbox history. The activity resembled normal user logins, which is why detection depended on account anomaly review rather than malware alerts.

The control that would have caught it· our reading, not a claim from the sources

Enforcing phishing-resistant MFA and automatically expiring or archiving mailbox contents containing PHI would have both blocked the login and limited what a single compromised account exposed.

Sources (1)

  1. Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents
    HIPAA Journal·hipaajournal.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.