Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - 4.5 Million Patient Records Accessed in CHS Hack
News & Analysis

4.5 Million Patient Records Accessed in CHS Hack

ISBuzz TeamBy ISBuzz TeamAugust 21, 2014Updated:July 5, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
$100 Million In Stolen Crypto Buried in Lazarus New Mixer
$100 Million In Stolen Crypto Buried in Lazarus New Mixer
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Community Health Systems, which runs 206 hospitals in the USA, has disclosed that its IT systems were breached over a three-month period, resulting in hackers gaining unauthorised access to the names, addresses and social security numbers of 4.5 million patients in the US.

Lucas Zaichkowsky, Enterprise Defence Architect at digital forensics and cyber incident response company AccessData, has commented on the potential motivation of the attackers for stealing patient names and addresses, “The hackers could feasibly identify individuals of interest or those who work at organisations of interest and use their personal details to craft convincing spear phishing emails. Another possibility is to simply bolster their overall intelligence by having data rich details on 4.5 million individuals.”

FREE Download: The Security Industry´s Dirty Little Secret

Commenting on the speculation that the CHS hack was carried out by Chinese state actors owing to similarities in the tactics employed as compared to those used in other attacks, Zaichkowsky said, “This is atypical for state-sponsored espionage. One possible motivation might be to gather intelligence on individuals which can be used in future cyber espionage campaigns. Chinese APT attack groups have been known to hoard interesting data while pursuing their intended objectives. It is well known in the intelligence community that healthcare is being heavily targeted by Chinese espionage efforts due to their large, aging population. Healthcare improvement is an objective in their current Five-Year Plan for economic development.”

Zaichkowsky continued, “HIPAA compliance certainly forces organisations to pay more attention to the secure handling of patient data. However, the likelihood of an organisation suffering a data breach is affected more strongly by what the active threat actors are pursuing. If an organisation has data that is sought after by a determined and skilled adversary, they have an extremely high likelihood of being breached, regardless of regulatory compliance requirements. Those organisations need to take security very seriously at the board level and allocate the resources necessary to mature their security operations to deal with real-world threats.”

By Lucas Zaichkowsky, Enterprise Defence Architect, AccessData

About AccessData

Access DataAccessData Group makes the world’s most advanced and intuitive incident resolution solutions. AccessData technology delivers real-time insight, analysis, response and resolution of data incidents, including cyber threats, insider threats, mobile and BYOD risk, GRC (Governance Risk & Compliance) and eDiscovery events. Over 130,000 users in corporations, law enforcement, government agencies, and law firms around the world rely on AccessData software to protect them against the risks present in today’s environment of continuous compromise. http://accessdata.com

References:

Computer Weekly, 19th August 2014, “4.5 million patient records exposed in US hospital group hack,” http://www.computerweekly.com/news/2240227011/45-million-patient-records-exposed-in-US-hospital-group-hack?asrc=EM_ERU_32870691&utm_medium=EM&utm_source=ERU&utm_campaign=20140819_ERU%20Transmission%20for%2008/19/2014%20(UserUniverse:%201011042)[email protected]&src=5287808

Wikipedia, “Five year plans of the People’s Republic of China”, http://en.wikipedia.org/wiki/Five-year_plans_of_the_People’s_Republic_of_China#Tenth_Plan_.282001.E2.80.932005.29

Recode, 18th August 2014, “Chinese hackers stole information on 4.5million US hospital patients,” http://recode.net/2014/08/18/chinese-hackers-stole-info-on-4-5-million-u-s-hospital-patients/

USA Today, 18th August 2014 “Community Health Systems hack attacks 4.5million”, http://www.usatoday.com/story/tech/2014/08/18/community-health-systems-hack-attack-45-million/14226421/

Fox Business, 18th August 2014, “China-based hackers steal 4.5million records crom Community Health Systems”,

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}