Full Report
Massachusetts’ Anna Jacques Hospital notifies over 316,000 patients of a data breach a year ago
Analysis Summary
# Incident Report: Anna Jacques Hospital Ransomware Breach
## Executive Summary
Anna Jacques Hospital, a non-profit community hospital in Massachusetts, suffered a ransomware breach that began in 2023 and was confirmed in late 2024, impacting over 316,000 individuals. The attackers accessed highly sensitive Protected Health Information (PHI) and financial data. The hospital discovered the initial breach on Christmas Day 2023, though the access confirmation only occurred in November 2024, resulting in a significant delay in public notification.
## Incident Details
- Discovery Date: December 25, 2023 (Initial suspicion/discovery)
- Incident Date: Prior to December 25, 2023 (Attack occurred/began)
- Affected Organization: Anna Jacques Hospital (Part of Beth Israel Lahey Health)
- Sector: Healthcare
- Geography: Newburyport, Massachusetts, USA
## Timeline of Events
### Initial Access
- Date/Time: Prior to December 25, 2023
- Vector: Ransomware attack (Specific initial vector—e.g., phishing, RDP—is not detailed in the source, but the outcome suggests unauthorized access occurred.)
- Details: Attackers gained access to the network, allowing for data theft.
### Lateral Movement
- Details: The attackers accessed and exfiltrated files containing sensitive patient and employee data, indicating successful internal reconnaissance and movement to areas holding valuable records.
### Data Exfiltration/Impact
- Date/Time: Data confirmed accessed/stolen by November 5, 2024 (Investigation conclusion). Data leaked by ransomware group (Money Message) in January 2024.
- Details: Compromise included demographic information, medical information, health insurance information, Social Security numbers (SSNs), driver’s license numbers, and financial information for 316,342 victims.
### Detection & Response
- Date/Time: Discovery on December 25, 2023. Investigation concluded November 5, 2024. Notification began December 6, 2024.
- Details: The hospital conducted a forensic investigation. Victims were notified starting December 6, 2024, "out of an abundance of caution," despite forensic confirmation in November 2024.
## Attack Methodology
- Initial Access: Inferred to be via a method allowing deployment of ransomware (likely leveraging vulnerability or social engineering, but **specific method is unstated**).
- Persistence: **Unknown**
- Privilege Escalation: **Unknown**
- Defense Evasion: **Unknown**
- Credential Access: **Unknown**
- Discovery: **Unknown**
- Lateral Movement: Confirmed successful movement to access patient and employee data files.
- Collection: Extensive collection of PII, PHI, and financial data.
- Exfiltration: Data was stolen and subsequently leaked by the Money Message ransomware group in January 2024.
- Impact: Encryption/disruption (implied by "ransomware breach") and massive data exfiltration.
## Impact Assessment
- Financial: Potential costs associated with investigation, litigation, regulatory fines, and identity protection services offered. No specific total estimated loss provided.
- Data Breach: Information for 316,342 individuals, including SSNs, driver's license numbers, medical records (PHI), and financial data.
- Operational: While not explicitly stated, a ransomware attack on a hospital implies significant operational disruption.
- Reputational: Significant reputational damage due to the breach occurring almost a year before victims were formally notified.
## Indicators of Compromise
*Note: Indicator details were not provided in the source article and cannot be confirmed.*
- Network indicators: [Not provided]
- File indicators: [Not provided]
- Behavioral indicators: [Not provided]
## Response Actions
- Containment measures: [Implied forensic investigation and system remediation followed containment, but specific measures are not detailed.]
- Eradication steps: [Not detailed, but presumed to involve remediation post-forensics.]
- Recovery actions: Offering two years of complimentary IdentityWorks Credit 3B for credit report monitoring, identity theft protection, and dark web monitoring to impacted individuals.
## Lessons Learned
- Delayed Notification: A significant gap existed between the initial discovery (Dec 2023) and the formal confirmation/notification (Dec 2024). This delay allowed threat actors to monetize the data for nearly a year before patient awareness.
- Data Sensitivity: The healthcare sector remains a high-value target due to the wealth of sensitive PII and PHI stored.
## Recommendations
- Improve Incident Reporting Timeliness: Establish and rigorously adhere to internal SLAs for forensic investigation completion and mandatory regulatory/victim notifications, regardless of preliminary certainty concerning the scope of impact.
- Enhance Ransomware Resilience: Review controls surrounding entry points, specifically focusing on preventing the initial access that leads to ransomware deployment.
- Strengthen Data Segmentation: Segment critical databases to limit the scope of data accessible during a ransomware event or lateral movement phase.