A data breach involving Mercy Regional Medical Center of Durango, Colo. exemplifies the stark reality that phishing attacks have become more complex and difficult for even the most shrewd of users to pick out.
Mercy employees, according to the Durango Herald, were the target of a phishing email attack in which the hackers tried to obtain user names and passwords. Some employees, under the impression it was an authentic email, responded and provided their system login information. Exactly what entity, perhaps Centura, the hackers were posing as is unknown at this point.
Centura Health, which owns Mercy, alerted 1,000 patients that their names, Social Security numbers, Medicare beneficiary numbers, addresses, dates of birth and phone numbers had been potentially accessed as a result of the hackers retrieving employee information. That list also includes protected health information (PHI) such as diagnoses, dates of service, names of a patient’s treating physician and medical-record numbers. The organization released a statement saying it is looking into the incident and brought in a forensics team to look at the affected employees’ email accounts. “When Centura learned of this, it was able to immediately stop the attack and began an investigation,” the statement read.
More specifically, Centura Health said that it took immediate steps to implement and reinforce necessary protective measures to help prevent future occurrences. “Those steps included immediately stopping the attack, performing an investigation and hiring an outside forensics expert to assist, reinforcing education to all employees regarding ‘phishing’ emails and continuing to implement enhancements for strengthening user login authentication,” the statement read.
Phishing attacks are nothing new in healthcare, but Centura Health’s incident is just the latest instance of a sophisticated social engineering scheme getting the best of a few employees. Just last month, Franciscan Health System of Tacoma, Wash. told 8,300 patients of a phishing attack that had compromised their data. Similar to Franciscan Health, Centura is smart to strongly emphasize to employees that underlying threats may seem benign on the surface, but they need a keen eye to determine whether an email is truly authentic or from a hacker.
There are indicators, such as misspellings or different email address than users had communicated with in the past, that users should have in the back of their minds as they perform normal, daily business activities. But the key is consistent reinforcement of proper phishing education internal employees, both new and old, within a healthcare organization.
