Michigan Medicine notifies patients of health information breach

Compromised employee email accounts could have exposed health information of about 56,953 patients

11:30 AM

Author | Mary Masson

medical campus aerial

ANN ARBOR, Mich. — Michigan Medicine is notifying approximately 56,953  individuals about employee email accounts that were compromised, potentially exposing some patient health information.

Three Michigan Medicine employee email accounts were compromised due to a cyberattack. The events occurred on May 23 and May 29, 2024. The accounts were disabled as soon as possible so no further access could take place.

This incident was not related to the recent CrowdStrike outages.

During its investigation, Michigan Medicine did not find any evidence to suggest that the aim of the attack was to obtain patient health information, but data theft could not be ruled out. As a result, all the emails involved were presumed compromised and the contents were reviewed to determine if sensitive data about patients was potentially impacted.This analysis took place between June 10, 2024, and June 27, 2024.

Some emails and attachments were found to contain identifiable patient and/or insurance guarantor information, such as: names, medical record numbers, addresses, dates of birth, diagnostic and treatment information, and/or health insurance information. The emails were job-related communications for payment and billing coordination for Michigan Medicine patients. The information involved for each specific patient varied, depending on the particular email or attachment. 

As soon as Michigan Medicine learned that the email accounts were compromised, the cyber attacker’s IP address was blocked, and immediate password changes were made so no further access could take place. The email accounts did not contain any credit card, debit card, or bank account numbers. Four patients received separate notice because their Social Security Numbers were involved.

Michigan Medicine is taking swift action to ward off future cyberattacks that target employees. Michigan Medicine has strengthened existing processes regarding the security of employee passwords and email accounts. Additionally, all Michigan Medicine staff will receive additional education on these topics, such as how social engineering attacks work, the need to select strong passwords, and the need to use different passwords for multiple sites. We are also strengthening existing processes to ward off social engineering attacks targeting Michigan Medicine employees.

“Michigan Medicine immediately took steps to investigate this matter, once alerted to the possibility of patient data being exposed. We constantly monitor for cyberattacks such as these because patient privacy is so extremely important to us,” said Jeanne Strickland, Michigan Medicine Chief Compliance Officer.

“We currently have multiple safeguards in place to reduce risk to our patients and prevent recurrence but will examine this incident thoroughly to determine if new or additional measures are needed.”

Notices were mailed to the affected patients and/or guarantors or their personal representatives starting July 19, 2024. Those concerned about the breach who do not receive a letter may call the toll-free Michigan Medicine Assistance Line: 1-888-409-7484. Calls will be answered Monday through Friday, 9 am to 9 pm (Eastern Time).

While Michigan Medicine does not have reason to believe the accounts were compromised for the purpose of obtaining patient information, as a precautionary measure, all affected patients have been advised to monitor their medical insurance statements for any potential evidence of fraudulent transactions. Information about potential identity theft is available from the Federal Trade Commission at www.identitytheft.gov/#/Warning-Signs-of-Identity-Theft

Media Contact Public Relations

Department of Communication at Michigan Medicine

[email protected]

734-764-2220

Related
Digital agreement hippa apps
Health Lab
Big Data Advances Research, But It Shouldn’t Do So at the Cost of Privacy
Health data collected from apps or wearable devices could revolutionize personalized healthcare, but the lack of legal protections related to this technology could lead to personal health information becoming available to unscrupulous third parties.
Featured News & Stories little girl in pain with pink background touching stomach and seeing inside red
Health Lab
Diagnostic stewardship optimizes detection of appendicitis
University of Michigan researchers found that emergency departments vary widely in how they balance the need to diagnose appendicitis with the potential harms of overtesting.
Well-Being at Michigan Medicine podcast - a part of the Michigan Medicine Podcast Network.
Well-Being at Michigan Medicine
Technology and Well-Being
In this episode, Dr. Elizabeth Harry is joined by Michigan Medicine’s Chief Information Officer Dr. Andrew Rosenberg. Harry and Rosenburg discuss how technology has aided and created hurdles to positive well-being in the medical setting. The two talk about the human focus, and ways data and innovation can be helpful in creating better relationships to reduce burnout.
white cream being put on finger close up with blurred red shirt in background of person using cream
Health Lab
Topical Mupirocin lowers lupus inflammation
J. Michelle Kahlenberg, M.D., Ph.D., led a team of researchers looking at an alternative treatment for lupus rashes with a topical treatment called mupirocin. 
cup sample with orange top in front of toilet
Health Lab
Urine-based test detects aggressive prostate cancer
Researchers at have validated a previously developed urine test, which can potentially bypass invasive procedures for prostate cancer detection among men who are unlikely to benefit. 
two men together walking outside
Health Lab
Exercise can reduce your cancer risk and help prevent its return
A director of exercise and health behavior in oncology shares ways to help cancer survivors live longer and better lives by incorporating exercise and other physical activity into everyday routines.
sink brushing pink toothbrush
Health Lab
Fluoride Q&A: An expert breaks down how it helps kids, and its unique history in Michigan
Sarah Clark, M.P.H., from the Department of Pediatrics at Michigan Medicine, answers what fluoride is and why it supports healthy teeth.