A hospital system in West Virginia suffered a data breach as a result of a phishing attack, which gave hackers access to several email accounts.

See also: Meta: Taking legal measures to combat phishing attacks
Monongalia Health System – which operates Monongalia County General Hospital Company and Stonewall Jackson Memorial Hospital Company – said hackers accessed multiple email accounts from May 10 to Aug. 15. Those accounts contained sensitive information from patients, providers, employees and contractors.
The company completed its investigation into the incident on October 29, finding that the attack stemmed from a phishing incident carried out via email.
“Mon Health was first made aware of the incident after a vendor reported that they had not received payment from Mon Health on July 28, 2021. In response, Mon Health immediately launched an investigation, through which it determined that unauthorized individuals had gained access to a Mon Health contractor email account and sent emails from the account in an attempt to obtain funds from Mon Health via fraudulent bank transfers,” the company explained.
“Upon learning of this, Mon Health secured the contractor’s email account and reset the password, notified law enforcement, and a third-party forensics firm was brought in to assist in the investigation.”
See also: Phishing attacks impersonate Pfizer
The attack did not include information from their other hospitals, such as Mon Health Preston Memorial Hospital and Mon Health Marion Neighborhood Hospital.

The company claims that "the purpose of the unauthorized access to the email accounts was to obtain funds from Mon Health through fraudulent bank transfers and to commit a phishing scheme, not to access personal information.".
Mon Health began sending breach notification letters to victims on December 21 and said they could call a call center without being charged to be notified of the incident.
See also: New study on phishing reveals some interesting findings
Dozens of healthcare organizations have had to send breach notification letters to patients due to cyberattacks or ransomware that exposed sensitive data.
Information source: zdnet.com
