Familylinks Inc., a nonprofit healthcare provider based in Pittsburgh, recently reported a data security incident that potentially exposed the personal and protected health information (PHI) of 3,775 individuals. The breach has now been linked to an employee’s email account
According to their official statement, on May 3, 2024, Familylinks discovered suspicious activity in an employee's email account. The organization states that they promptly engaged independent cybersecurity experts and launched an investigation to determine the scope of the incident.
The investigation revealed that emails and attachments within the compromised account may have been accessed without authorization on the same day. Following a detailed data review, completed on October 3, 2024, Familylinks identified that certain individuals’ PHI and personal information were affected.
The potentially exposed data includes sensitive details such as:
Although there is no evidence suggesting misuse of the data, the exposure of this information presents a risk of identity theft and other potential misuse.
According to their official press release on the incident, Familylinks took immediate action to notify individuals whose data may have been affected. On October 3, 2024, notification letters were sent via U.S. mail to those with verified addresses, with guidance on protecting their information and addressing concerns. A toll-free call center was also established to answer questions and assist individuals.
Familylinks advises all affected individuals to take the following steps to protect their information:
Additional resources on identity theft prevention are available through the Federal Trade Commission (FTC) at www.ftc.gov/idtheft.
Phishing attacks are the most common cause, where attackers trick employees into sharing login credentials or clicking malicious links, granting unauthorized access to email accounts.
Yes, if PHI is exposed through compromised internal emails, it still constitutes a HIPAA violation, as unauthorized access to protected information breaches privacy regulations.
An incident response plan should include steps for isolating affected accounts, notifying impacted individuals, conducting a root cause analysis, and reporting to regulatory authorities if required.