Phishers broke into a small set of staff email accounts at a West Virginia hospital in early May, and the facility is now alerting patients that personal and medical records may have been swept into the intrusion. Mon General, the name used by the operator of Monongalia County General Hospital, said the attack surfaced May 6 and that access was terminated the same day.
A forensic security provider finished its review in late June and found that no other data storage or hospital systems were affected, the hospital said. The types of records at risk vary by person and can include names, dates of birth, email addresses, phone numbers, Social Security numbers, and health or insurance details.
Healthcare remains a favorite target for phishing campaigns, and smaller community hospitals often lack the staff to catch every lure. Mon General has not said how many patients received letters or whether any stolen data has been used fraudulently.
Anyone who gets a notice should check account statements and consider a credit freeze or monitoring if their Social Security number was involved. Hospitals that see mailbox compromises should force password resets, roll out multi-factor authentication, and keep a tested notification playbook ready.
