UnityPoint Health suffers breach; 1.4 million patient records compromised

Date:

Share post:

Lowa-based health system UnityPoint Health has fallen victim to a recent data heist that compromised 1.4 million patient records. According to an official statement from the company, the issue began when UnityPoint Health received a series of phishing emails that trapped some employees to provide their sign-in credentials. This gave the hackers unauthorized access to the company’s business email accounts. The organization discovered the incident on May 31, 2018, and notified the victims about the data theft.

Around 1.4 million people are being informed about the unauthorized access to protected personal and health information by compromising the company’s business email system. The health system stated that the fraudulent emails were designed to appear to have come from a trusted executive within the organization. The compromised data included patients’ names, addresses, dates of birth, medical record numbers, treatment and surgical information, diagnoses, lab results, medications, dates of service, and insurance information.

The health system stated that they’ve informed law enforcement authorities about the data heist and launched an investigation with a computer forensics firm. To prevent further loss, the health system implemented a multi-factor authentication to verify the users before accessing their accounts and educated employees to identify and avoid phishing emails or attachments.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...

SBOM, VEX, and AI: Dr. Allan Friedman on the Future of Software Supply Chain Security

A conversation on why software transparency is no longer optional, and how AI is about to make it...

Model-Borne Consequence: Why OT Security and Data Security Just Became the Same Job

For thirty years we told you industrial cybersecurity was fundamentally different from IT cybersecurity. We were right. Then...

Truth, Transparency, and a Subpoena: Inside TikTok’s Security Crisis with Roland Cloutier

How the former ByteDance CISO led a 3-billion-user platform through congressional hearings, an international ban threat, and the...