Guam Seventh-Day Adventist Clinic email breach exposed 56,635 people
- Organization
- Guam Seventh-Day Adventist Clinic
- Exploit
- Hacking
- Industry
- Healthcare
Guam Seventh-Day Adventist Clinic, a healthcare provider based in Tamuning, Guam, began notifying patients in September 2024 that a limited number of employee email accounts had been accessed by an unauthorized party. The clinic said the intrusion took place between January 23 and February 3, 2023.
The review of the affected mailboxes ran for more than a year. On August 6, 2024, the clinic concluded that personal and protected health information held in those accounts had been exposed and may have been acquired. According to HIPAA Journal, the data varied from person to person and could include names, addresses, phone numbers, email addresses, dates of birth, financial account and routing numbers, payment card information, usernames and passwords, driver's license and government identification numbers, Social Security numbers, medical record and patient account numbers, diagnosis and treatment details, and health insurance information.
The clinic reported the incident as affecting 56,635 individuals, a figure that also appears in federal breach reporting summaries for September 2024. Not every category of data was involved for every person notified.
The clinic posted a notice on its website when the compromise was identified and said the delay in mailing letters was the result of the time the investigation took. It said it had put additional cybersecurity safeguards in place, revised its policies, procedures and protocols, and expanded employee security training. As of the September 2024 reports, no misuse of the information had been identified.