Michigan Medicine notifies patients of health information breach

Compromised employee email accounts could have exposed health information of about 56,953 patients

11:30 AM

Author | Mary Masson

medical campus aerial

ANN ARBOR, Mich. — Michigan Medicine is notifying approximately 56,953  individuals about employee email accounts that were compromised, potentially exposing some patient health information.

Three Michigan Medicine employee email accounts were compromised due to a cyberattack. The events occurred on May 23 and May 29, 2024. The accounts were disabled as soon as possible so no further access could take place.

This incident was not related to the recent CrowdStrike outages.

During its investigation, Michigan Medicine did not find any evidence to suggest that the aim of the attack was to obtain patient health information, but data theft could not be ruled out. As a result, all the emails involved were presumed compromised and the contents were reviewed to determine if sensitive data about patients was potentially impacted.This analysis took place between June 10, 2024, and June 27, 2024.

Some emails and attachments were found to contain identifiable patient and/or insurance guarantor information, such as: names, medical record numbers, addresses, dates of birth, diagnostic and treatment information, and/or health insurance information. The emails were job-related communications for payment and billing coordination for Michigan Medicine patients. The information involved for each specific patient varied, depending on the particular email or attachment. 

As soon as Michigan Medicine learned that the email accounts were compromised, the cyber attacker’s IP address was blocked, and immediate password changes were made so no further access could take place. The email accounts did not contain any credit card, debit card, or bank account numbers. Four patients received separate notice because their Social Security Numbers were involved.

Michigan Medicine is taking swift action to ward off future cyberattacks that target employees. Michigan Medicine has strengthened existing processes regarding the security of employee passwords and email accounts. Additionally, all Michigan Medicine staff will receive additional education on these topics, such as how social engineering attacks work, the need to select strong passwords, and the need to use different passwords for multiple sites. We are also strengthening existing processes to ward off social engineering attacks targeting Michigan Medicine employees.

“Michigan Medicine immediately took steps to investigate this matter, once alerted to the possibility of patient data being exposed. We constantly monitor for cyberattacks such as these because patient privacy is so extremely important to us,” said Jeanne Strickland, Michigan Medicine Chief Compliance Officer.

“We currently have multiple safeguards in place to reduce risk to our patients and prevent recurrence but will examine this incident thoroughly to determine if new or additional measures are needed.”

Notices were mailed to the affected patients and/or guarantors or their personal representatives starting July 19, 2024. Those concerned about the breach who do not receive a letter may call the toll-free Michigan Medicine Assistance Line: 1-888-409-7484. Calls will be answered Monday through Friday, 9 am to 9 pm (Eastern Time).

While Michigan Medicine does not have reason to believe the accounts were compromised for the purpose of obtaining patient information, as a precautionary measure, all affected patients have been advised to monitor their medical insurance statements for any potential evidence of fraudulent transactions. Information about potential identity theft is available from the Federal Trade Commission at www.identitytheft.gov/#/Warning-Signs-of-Identity-Theft

Media Contact Public Relations

Department of Communication at Michigan Medicine

[email protected]

734-764-2220

Related
Digital agreement hippa apps
Health Lab
Big Data Advances Research, But It Shouldn’t Do So at the Cost of Privacy
Health data collected from apps or wearable devices could revolutionize personalized healthcare, but the lack of legal protections related to this technology could lead to personal health information becoming available to unscrupulous third parties.
Featured News & Stories
Health Lab
Heat wave survival tips from a U-M emergency physician
How to avoid or recognize heat exhaustion or heat stroke, what groups of people are most at risk of these heat-related illnesses, and heat wave power outage tips
man dirt biking jumping hill in woods
Health Lab
Doctor helps one father’s race against lung cancer
Successful treatment of ALK-positive cancer is giving a patient hope for the future that includes trips around the motocross track and time with his wife and four kids.
Patient at desk drinking a fluid
Health Lab
5 hot weather tips that could save an older adult’s life
Health professionals offer five tips to help older adults stay safe and healthy during excessive heat wave.
sleeping baby
Health Lab
How to protect your baby from the dangers of hot weather
A University of Michigan pediatrician discusses the importance of keeping babies safe in hot weather. See her tips on protecting your baby from the heat.
Health Lab Podcast in brackets with a background with a dark blue translucent layers over cells
Health Lab Podcast
Allergies feeling amplified?
Today on Health Lab, we highlight how to treat seasonal allergies, and why allergy seasons are getting more severe. You can read the full article on the Health Lab website.
Gameday room renovation ribbon cutting
News Release
C.S. Mott Children’s Hospital unveils renovated indoor playground for kids
ANN ARBOR, Mich. – Children and families at University of Michigan Health C.S. Mott Children’s Hospital celebrated the reopening of the hospital’s newly renovated Michigan Game Day Experience playroom.