MedStar Health email breach exposed data on about 183,000 patients

Organization
MedStar Health
Exploit
Hacking
Industry
Healthcare

MedStar Health, a not-for-profit health system serving the Washington DC and Maryland region, disclosed in May 2024 that an unauthorized party had gained access to the email accounts of three employees.

The access happened intermittently between 25 January and 18 October 2023. MedStar said a forensic review completed on 6 March 2024 established that emails and files in those accounts contained patient information. The system reported the breach to the US Department of Health and Human Services as affecting about 183,000 people, with individual outlets citing counts of 183,079 and 183,709.

The information involved included patient names, mailing addresses, dates of birth, dates of service, provider names and health insurance information. MedStar said it had no reason to believe patient information was actually acquired or viewed, but that it "cannot rule out such access."

MedStar began notifying affected patients, apologized for any concern caused and said it had implemented additional safeguards. It advised patients to review statements from insurers and providers for services they did not receive. The system did not explain publicly how the three accounts were compromised and declined to comment further to reporters covering the disclosure.

Sources