[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3j370nk5ym7f1":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"6a705ab58c2675c47d81cfef","WeiserMemorialHospital2024","Weiser Memorial Hospital 2024 Data Breach","weiser-memorial-hospital-2024","weisermemorialhospital.org","2024-09-04T00:00:00.000Z","2026-08-03T09:09:09.187Z","Official hospital notice, HHS OCR report, and independent healthcare-security reporting","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",[14,16,17,18],"https:\u002F\u002Fwww.weisermemorialhospital.org\u002Ffiles\u002Fnews\u002FWeiser-Substitute-Notice.pdf","https:\u002F\u002Fwww.hipaajournal.com\u002Fweiser-memorial-hospital-data-breach\u002F","https:\u002F\u002Fwww.weisermemorialhospital.org\u002F",59990,"known",null,"people","Medium",[25,26,27,28,29,30],"Names","Dates of birth","Social security numbers","Government issued IDs","Medical information","Health insurance information","\u003Cp>\u003Cstrong>The 2024 Weiser Memorial Hospital data breach\u003C\u002Fstrong> came to light after the Idaho hospital detected unusual activity on its network on September 4, 2024. The investigation found that certain hospital data may have been accessed and acquired without authorization on or around that date.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights records the event as a network-server Hacking\u002FIT Incident affecting 59,990 people. The hospital's official notice confirms that identity and health information belonging to current and former patients may have been involved.\u003C\u002Fp>\u003Ch2>How was the Weiser Memorial Hospital breach confirmed?\u003C\u002Fh2>\u003Cp>Weiser Memorial Hospital's official notice connects the September 4, 2024 discovery and possible data-acquisition date, completion of the file review on April 21, 2025, and the disclosed information types in one event. The HHS OCR entry confirms the organization, the Idaho healthcare provider, and the current total of 59,990 people.\u003C\u002Fp>\u003Cp>Independent healthcare-security reporting also describes the September 4 event, data exfiltration, the April 21 review-completion date, and the 59,990-person scope. An earlier published total of 34,249 was increased to 59,990 in the later HHS update; the figures were not added together.\u003C\u002Fp>\u003Ch2>What happened on September 4, 2024?\u003C\u002Fh2>\u003Cp>The hospital detected unusual activity on its network on September 4, secured its systems, and engaged cybersecurity specialists to determine the nature and scope of the event. The investigation confirmed that an unauthorized party accessed network files and may have acquired them.\u003C\u002Fp>\u003Cp>An independent event summary attributes the attack to the EMBARGO ransomware group and reports the group's claim that it took 200 GB of data. The hospital's official statement confirms possible unauthorized data acquisition but does not itself name the actor, verify the volume claim, disclose the initial access method, or identify a technical vulnerability.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>Depending on the person, potentially affected information included names, dates of birth, Social Security numbers, or other government identification numbers. Disclosed health fields included diagnoses, treatment or procedure information, and Medicare, Medicaid, or health insurance information.\u003C\u002Fp>\u003Cp>The hospital says the affected fields were not the same for every person. Email addresses, passwords, payment cards, and bank accounts are not included in this record because the official notice does not confirm those fields.\u003C\u002Fp>\u003Ch2>Why do these details matter?\u003C\u002Fh2>\u003Cp>Identity numbers exposed together with diagnosis, treatment, and insurance information can increase the risk of identity theft, fraudulent healthcare claims, and targeted scams. Social Security and government identification numbers are difficult to change, so careful monitoring may be necessary over the long term.\u003C\u002Fp>\u003Cp>Someone who knows a real diagnosis, procedure, or insurance detail may craft a more convincing message. Possessing those details does not prove that a sender represents Weiser Memorial Hospital, a physician, or an insurer, and unexpected requests should be verified through an independent channel.\u003C\u002Fp>\u003Ch2>How did the hospital respond?\u003C\u002Fh2>\u003Cp>Weiser Memorial Hospital secured its systems, investigated with external cybersecurity specialists, and conducted a comprehensive review to identify affected files and people. The review concluded on April 21, 2025, and notices were sent to people with available mailing addresses.\u003C\u002Fp>\u003Cp>The hospital said it implemented additional measures to strengthen network security and established a call center. Eligible individuals were offered credit monitoring, a credit report, and credit-score services; public sources do not claim that these measures identified the initial technical cause.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>People who received a notice should regularly review credit reports, financial accounts, and health insurance explanations for unfamiliar accounts, transactions, services, or claims. Suspicious entries should be reported to the relevant financial institution, health insurer, and appropriate authorities when necessary.\u003C\u002Fp>\u003Cp>Social Security numbers, health information, passwords, and one-time verification codes should not be shared in unexpected emails, messages, or calls. A request claiming to come from the hospital should be verified using contact information on Weiser Memorial Hospital's official website rather than a link or phone number in the message.\u003C\u002Fp>","","Weiser Memorial Hospital 2024 Data Breach (60 Thousand People Affected)","The Weiser Memorial Hospital breach may have exposed identity and health data belonging to 59,990 people.","\u002Fuploads\u002Flogo\u002Fweiser-memorial-hospital-official.svg",false,{"name":38,"sector":39,"country":40,"website":18,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Weiser Memorial Hospital","Healthcare","United States"]