Michigan Medicine notifies about 57,000 patients after email account breach

Organization
Michigan Medicine
Exploit
Hacking
Industry
Healthcare

Michigan Medicine, the academic health system of the University of Michigan, began notifying roughly 57,000 patients and insurance guarantors in July 2024 that their information may have been exposed after employee email accounts were compromised. CBS News Detroit put the figure at 56,953 and reported that three staff accounts were involved.

The health system said unauthorized access occurred on May 23 and May 29, 2024. Investigators reviewed the contents of the affected mailboxes between June 10 and June 27 and treated every message in them as compromised. The exposed material varied by individual and included names, addresses, dates of birth, medical record numbers, diagnostic and treatment information, and health insurance details. Social Security numbers were involved for four patients. No credit card, debit card or bank account numbers were affected.

Michigan Medicine said it found no evidence that the attackers were specifically seeking patient health information, but it could not rule out data theft. The compromised accounts were disabled once the activity was identified, the attacker's IP address was blocked and employee passwords were reset.

Notification letters were mailed starting July 19, 2024, and the health system opened a toll free assistance line for patients who had questions or had not received a letter. It said it would strengthen email security controls and provide additional staff training on social engineering and password practices, and would examine whether further measures were needed.

Sources