Michigan Medicine notifies patients of health information breach

Compromised employee email accounts could have exposed health information of about 33,850 patients

Authors | Mary Masson | Beata Mostafavi

Michigan Medicine is notifying approximately 33,850 patients about employee email accounts that were compromised which may have exposed some of their health information.

From August 15 through August 23, 2022, a cyber attacker targeted Michigan Medicine employees with an email “phishing” scam. In this scam, the attacker lured employees to a webpage designed to get them to enter their Michigan Medicine login information. Four Michigan Medicine employees entered their login information and then inappropriately accepted multifactor authentication prompts which allowed the cyber attacker to access their Michigan Medicine e-mail accounts. Michigan Medicine learned the email accounts were compromised on August 23, 2022. The accounts were disabled as soon as possible so no further access could take place and password changes were made.

No evidence was uncovered during the investigation to suggest that the aim of the attack was to obtain patient health information from the compromised email accounts, but data theft could not be ruled out. As a result, the email accounts and their contents were presumed compromised.  Thus, all the emails and any attachments to them required a detailed, thorough review to determine if sensitive data about one or more patients was potentially impacted. This review was completed on October 17, 2022. Affected patients will be notified by letter. Notices were mailed to the affected patients or their personal representatives starting October 19, 2022 and will be completed on October 26, 2022. 

Some emails and attachments were found to contain identifiable patient information such as:  Name; medical record number; address; date of birth; diagnostic and treatment information; and/or health insurance information. The emails were job-related communications for coordination and care of patients, and information related to a specific patient varied, depending on a particular email or attachment.

As soon as Michigan Medicine learned that the email accounts were compromised, the accounts were disabled so no further access could take place and immediate password changes were made. Additional technical safeguards on our email system and the infrastructure that supports it were also put in place to prevent similar incidents from happening. The email accounts did not contain any credit card, debit card or bank account numbers. One patient received separate notice because their Social Security Number was involved.  

Robust training and education materials are used to increase employee awareness of the risks of cyberattacks. This includes sending regular, simulated phishing emails (imitations) that Michigan Medicine initiates and manages so employees are trained on what to look for, and how to identify and report them. The employees involved in this incident had previously been involved in these training exercises, and they are subject to disciplinary action under Michigan Medicine policies and procedures. Michigan Medicine is very sorry and deeply regrets this incident has occurred.  Michigan Medicine also is assessing the ability to place additional technical safeguards on our email system and the infrastructure that supports it to prevent similar incidents from happening.

“Patient privacy is extremely important to us, and we take this matter very seriously. Michigan Medicine took steps immediately to investigate this matter and is implementing additional safeguards to reduce risk to our patients and help prevent recurrence,” said Jeanne Strickland, Michigan Medicine chief compliance officer.

Those concerned about the breach who do not receive a letter may call the toll-free Michigan Medicine Assistance Line: 1-833-814-1736. Calls will be answered from 9 a.m. to 9 p.m. (Eastern Time), Monday through Friday, except holidays.  

 While Michigan Medicine does not have reason to believe the accounts were compromised for the purpose of obtaining patient information, as a precautionary measure, all affected patients have been advised to monitor their medical insurance statements for any potential evidence of fraudulent transactions. Information about potential identity theft is available from the Federal Trade Commission at www.identitytheft.gov/#/Warning-Signs-of-Identity-Theft.

About Michigan Medicine: At Michigan Medicine, we advance health to serve Michigan and the world. We pursue excellence every day in our five hospitals, 125 clinics and home care operations that handle more than 2.3 million outpatient visits a year, as well as educate the next generation of physicians, health professionals and scientists in our U-M Medical School.

Michigan Medicine includes the top ranked U-M Medical School and University of Michigan Health, which includes the C.S. Mott Children’s Hospital, Von Voigtlander Women’s Hospital, University Hospital, the Frankel Cardiovascular Center, University of Michigan Health-West  and the Rogel Cancer Center. The U-M Medical School is one of the nation's biomedical research powerhouses, with total research funding of more than $500 million.

Media Contact Public Relations

Department of Communication at Michigan Medicine

[email protected]

734-764-2220

Featured News & Stories girl sitting on couch with brace on and standing with brace on in UM shirts
Health Lab
Live donor cartilage allows musician to return to the stage
A musician receives live donor cartilage that changes her life.
doctor in white coat with dark blue scrubs touching hand of patient in grey sweater and baseball cap in exam room
Health Lab
Neuropathy common, and mostly undiagnosed, among patients in this Michigan city
A research team, led by Michigan Medicine and in partnership with Hurley Medical Center, finds that nearly three-quarters of patients at a clinic in Flint, Mich., a community that is predominantly Black and socioeconomically disadvantaged, had neuropathy — of which 75% was undiagnosed.
cancer cell blue yellow
Health Lab
Widening inequality seen where cancer clinical trials are available
The availability of clinical trials of new treatments for cancer varies greatly by geography, and a new study shows more socially vulnerable areas have far fewer.
man in black polo folded arms smiling no teeth bright orange background
Health Lab
Comedy and medicine
An ophthalmologist and beloved comedian shares his thoughts on the field to aspiring clinicians.
man smiling with cupcakes glasses
Health Lab
Two heart transplants, one message for organ donation
A patient who has received two heart transplants years apart shares his story and the importance of advocating for organ donation.
The Fundamentals Podcast Hero Card Final 1800 x 1350
The Fundamentals
Cannabis and psychedelics: stigmatized substances or powerful therapeutics?
Today on The Fundamentals is Dr. Kevin Boehnke, research assistant professor in the Department of Anesthesiology and the Chronic Pain and Fatigue Research Center. His current research focuses on therapeutic applications of cannabis and psychedelics. His goal is to rigorously assess appropriate use of these substances and to help address the public health harms caused by their criminalization.