Royal Women's Hospital notified 192 patients after staff email account hacked
- Organization
- The Royal Women's Hospital
- Exploit
- Credential Compromise
- Industry
- Healthcare
The Royal Women's Hospital in Melbourne told patients in early October 2023 that cyber criminals had gained access to the private email account of a staff member. The account had been used to review and coordinate patient appointments and care plans, including from home.
A forensic investigation by external cyber security specialists found that personal information belonging to 192 patients may have been exposed. The hospital said there was no breach of its official email system or its wider IT infrastructure, and that patient electronic medical records remained secure.
Most of the affected patients were contacted directly on the morning of October 5, with the remainder notified by registered mail. The hospital set up a dedicated hotline where patients could speak to cyber specialists for identity protection advice, and offered free counselling. It apologised for the distress and inconvenience caused.
The hospital did not name a threat actor and no group claimed responsibility. The Cyber Express reported that one patient said the hospital was able to confirm at that stage what of her information had appeared on the dark web, but that there was no guarantee it would not appear in future. As of the reporting date the hospital had not revised the number of affected patients.