Jefferson Healthcare breach possibly affects 2,550 people

Phishing attack hits employee email, not medical, financial records

PORT‌ ‌TOWNSEND — Some 2,550 people may have had personal information taken during a phishing attack on a ‌‌Jefferson‌ ‌Healthcare‌ hospital employee’s email account, according to a hospital spokesperson.

All have been notified.

The attack, which occurred on Nov. 12, did not get into any systems outside the email account, said Amy Yaley, Jefferson Healthcare marketing and communications director, in an email released late Monday.

‌ “At‌ ‌this‌ ‌time,‌ ‌Jefferson‌ ‌Healthcare‌ ‌has‌ ‌a‌ ‌reasonable‌ ‌basis‌ ‌to‌ ‌believe‌ ‌that‌ ‌there‌ ‌has‌ ‌not‌ ‌been‌ ‌any‌ ‌improper‌ ‌access‌ ‌to‌ ‌its‌ electronic‌ ‌medical‌ ‌record‌ ‌system,‌ ‌billing‌ ‌systems,‌ ‌or‌ ‌other‌ ‌systems‌ ‌outside‌ ‌of‌ ‌the‌ ‌affected‌ ‌email‌ ‌account,‌ ‌or‌ ‌that‌ ‌the‌ ‌incident‌ ‌has‌ ‌affected‌ ‌or‌ ‌will‌ ‌affect‌ ‌any‌ ‌patient‌ ‌care,” Yaley’s email said.‌ ‌

Most information was not especially sensitive, but in 84 cases, Social Security numbers or financial information may have been disclosed, she said Tuesday.

‌Jefferson‌ ‌Healthcare‌ ‌has‌ ‌arranged‌ ‌for‌ ‌those people ‌to‌ ‌enroll‌ ‌in‌ ‌a‌ ‌credit‌ ‌monitoring‌ ‌service‌ ‌through‌ ‌Experian‌ ‌at‌ ‌no‌ ‌cost‌ ‌to‌ ‌the‌ ‌individuals, she added.

“Affected‌ ‌individuals‌ ‌should‌ ‌take‌ ‌steps‌ ‌to‌ ‌protect‌ ‌their‌ ‌identity‌ ‌and‌ ‌monitor‌ ‌their‌ ‌credit‌ ‌file,” Yaley said.

The employee whose email account had been attacked responded to what appeared to be a DocuSign document. Then she noticed emails were sent from her address to other people in her address books, Yaley said.

Jefferson Healthcare quickly contacted those 658 people to tell them not to open the document, Yaley said.

At same time, the hospital’s IT crew checked to see if the phishers had penetrated the firewall.

“They did not breach the firewall,” Yaley said, adding that the phishers did not get to financial records.

The computer was taken offline as soon as the breach was discovered. The phishers were in the system for about three days, Yaley said.

The hospital ‌hired‌ ‌two‌ ‌forensic‌ ‌specialist‌ ‌companies‌ ‌to‌ ‌determine‌ ‌the‌ ‌nature‌ ‌and‌ ‌extent‌ ‌of‌ ‌the‌ ‌ unauthorized‌ ‌access‌ ‌and‌ ‌email‌ ‌breach‌ ‌and‌ ‌to‌ ‌determine‌ ‌if‌ ‌personal‌ ‌information‌ ‌was‌ ‌involved, Yaley said.‌ ‌ ‌

The investigators combed through 30,000 .pdf documents and attachments to find everyone who might have been affected. They finished their work in the week between Christmas and New Year’s, Yaley said, and those who were found were sent notice on Monday.

“Based‌ ‌on‌ ‌Jefferson‌ ‌Healthcare’s‌ ‌security‌ ‌practices‌ ‌and‌ ‌investigation‌ ‌of‌ ‌the‌ ‌incident,‌ ‌it‌ ‌is‌ ‌reasonably‌ ‌believed‌ ‌that relatively‌ ‌few‌ ‌documents‌ ‌were‌ ‌likely‌ ‌viewed‌ ‌by‌ ‌the‌ ‌unauthorized‌ ‌parties‌ ‌during‌ ‌their‌ ‌brief‌ ‌access‌ ‌to‌ ‌the‌ ‌affected‌ ‌email account,” she added.

“However,‌ ‌the‌ ‌investigation‌ ‌could‌ ‌not‌ ‌definitively‌ ‌conclude‌ ‌that‌ ‌the‌ ‌unauthorized‌ ‌parties‌ ‌did‌ ‌not‌ ‌access‌ ‌certain information‌ ‌and‌ ‌documents‌ ‌stored‌ ‌in‌ ‌the‌ ‌affected‌ ‌email‌ ‌account.”

Other potentially‌ ‌exposed‌ ‌information‌ included an individual’s‌ ‌full‌ ‌name,‌ ‌date‌ ‌of‌ ‌birth,‌ ‌phone‌ ‌number,‌ ‌home‌ ‌address,‌ ‌health‌ ‌insurance‌ ‌information,‌ ‌certain‌ ‌health‌ information‌ ‌such‌ ‌as‌ ‌dates‌ ‌of‌ ‌service,‌ ‌and‌ ‌diagnosis‌ ‌and‌ ‌treatment‌ ‌information.‌

Yasley also said Jefferson Healthcare has taken preventative measures such as adding ‌anti-fraud‌ ‌technology‌ ‌safeguards‌ ‌and‌ ‌other‌ ‌cybersecurity‌ ‌risk‌ ‌prevention‌ ‌measures; reinforcing‌ ‌education‌ ‌and‌ ‌training‌ ‌for‌ ‌its‌ ‌staff‌ ‌members‌ ‌on‌ ‌how‌ ‌to‌ ‌avoid‌ ‌email‌ ‌phishing‌ ‌schemes‌ ‌and‌ ‌how‌ ‌to‌ ‌properly‌ ‌secure‌ ‌login‌ ‌credentials; and reviewing‌ ‌its‌ ‌policies‌ ‌and‌ ‌procedures‌ ‌to‌ ‌ensure‌ ‌they‌ ‌sufficiently‌ ‌protect‌ ‌against‌ ‌more such ‌incidents.

“Jefferson‌ ‌Healthcare‌ ‌takes‌ ‌individual‌ ‌privacy,‌ ‌and‌ ‌the‌ ‌trust‌ ‌of‌ ‌our‌ ‌community,‌ ‌seriously‌ ‌and‌ ‌has‌ ‌taken‌ ‌immediate‌ ‌steps‌ ‌to‌ ‌enhance‌ ‌our‌ ‌information‌ ‌security‌ ‌systems,” said‌ ‌Brandie‌ ‌Manuel,‌ ‌chief‌ patient‌ safety‌ ‌and‌ quality‌ ‌officer.

“We‌ ‌continue‌ ‌to‌ ‌be‌ ‌vigilant‌ ‌resolving‌ ‌security‌ ‌threats‌ ‌as‌ ‌they‌ ‌are‌ ‌identified‌ ‌and‌ ‌educating‌ ‌our‌ ‌staff‌ ‌members. ‌We‌ ‌are‌ ‌committed‌ ‌to‌ ‌transparency‌ ‌and‌ ‌sincerely‌ ‌apologize‌ ‌to‌ ‌those‌ ‌who‌ ‌have‌ ‌been‌ ‌impacted‌ ‌by‌ ‌this‌ ‌breach.”‌ ‌

It is not known who beached the computer.

“These things (phishing emails) look good. They are very sophisticated,” Yaley said. “All of us are going to have to continue to be more and more aware of what’s out there.

“They are after any information they can get.”

________

Executive Editor Leah Leach can be reached at 360-417-3530 or at lleach@peninsuladailynews.com.

More in News

Sue Long, left, Vicki Bennett and Frank Handler, all from Port Townsend, volunteer at the Martin Luther King Day of Service beach restoration on Monday at Fort Worden State Park. The activity took place on Knapp Circle near the Point Wilson Lighthouse. Sixty-four volunteers participated in the removal of non-native beach grasses. (Steve Mullensky/for Peninsula Daily News)
Work party

Sue Long, left, Vicki Bennett and Frank Handler, all from Port Townsend,… Continue reading

Portion of bridge to be replaced

Tribe: Wooden truss at railroad park deteriorating

Kingsya Omega, left, and Ben Wilson settle into a hand-holding exercise. (Aliko Weste)
Process undermines ‘Black brute’ narrative

Port Townsend company’s second film shot in Hawaii

Jefferson PUD to replace water main in Coyle

Jefferson PUD commissioners awarded a $1.3 million construction contract… Continue reading

Scott Mauk.
Chimacum superintendent receives national award

Chimacum School District Superintendent Scott Mauk has received the National… Continue reading

Hood Canal Coordinating Council meeting canceled

The annual meeting of the Hood Canal Coordinating Council, scheduled… Continue reading

Bruce Murray, left, and Ralph Parsons hang a cloth exhibition in the rotunda of the old Clallam County Courthouse on Friday in Port Angeles. The North Olympic History Center exhibit tells the story of the post office past and present across Clallam County. The display will be open until early February, when it will be relocated to the Sequim City Hall followed by stops on the West End. The project was made possible due to a grant from the Clallam County Heritage Advisory Board. (Dave Logan/for Peninsula Daily News)
Post office past and present

Bruce Murray, left, and Ralph Parsons hang a cloth exhibition in the… Continue reading

This agave grew from the size of a baseball in the 1990s to the height of Isobel Johnston’s roof in 2020. She saw it bloom in 2023. Following her death last year, Clallam County Fire District 3 commissioners, who purchased the property on Fifth Avenue in 2015, agreed to sell it to support the building of a new Carlsborg fire station. (Matthew Nash/Olympic Peninsula News Group file)
Fire district to sell property known for its Sequim agave plant

Sale proceeds may support new Carlsborg station project

As part of Olympic Theatre Arts’ energy renovation upgrade project, new lighting has been installed, including on the Elaine and Robert Caldwell Main Stage that allows for new and improved effects. (Olympic Theatre Arts)
Olympic Theatre Arts remodels its building

New roof, LED lights, HVAC throughout

Weekly flight operations scheduled

Field carrier landing practice operations will be conducted for aircraft… Continue reading

Workers from Van Ness Construction in Port Hadlock, one holding a grade rod with a laser pointer, left, and another driving the backhoe, scrape dirt for a new sidewalk of civic improvements at Walker and Washington streets in Port Townsend on Thursday. The sidewalks will be poured in early February and extend down the hill on Washington Street and along Walker Street next to the pickle ball courts. (Steve Mullensky/for Peninsula Daily News)
Sidewalk setup

Workers from Van Ness Construction in Port Hadlock, one holding a grade… Continue reading