25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Verity Health System Victim of Phishing Attack

Verity Health System has fallen victim to a phishing attack resulting in sensitive employee data being emailed outside the company. Employee names, addresses, Social Security numbers, amount earned in the financial year, and details of tax withheld have been disclosed to the attacker.

The breach only affected past and present employees who would have received a W-2 for the past financial year. No patient data was compromised in the breach.

An email was received on April 27, 2016., which appeared to have been sent from an individual inside the organization. The email asked for information on Verity employees, which was sent as requested. The scam was discovered just over three weeks later.

The Oregon-based healthcare provider is one of a large number of companies that have fallen victim to this kind of scam this year. These phishing attacks are often referred to as business email compromise scams, although internal email accounts are not always compromised. Oftentimes, attackers purchase a similar domain to that used by the targeted organization. The letter ‘I’ could be replaced with a 1 for example. A casual glance at the sender’s email address would not reveal anything untoward.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Attackers only need to perform a minimal amount of research to find out the name of the CEO or another high ranking executive in the company, together with a target in the accounts or HR department. An email account is then set up using the same format as that used by the company and the email request for data is sent.

The IRS issued a warning to U.S organizations earlier this year alerting them to a significant increase in this type of scam in the first few months of 2016.

Business email compromise scams are highly effective as many employees do not question requests from the CEO or C-suite executives. In many cases, requests for employee data seem perfectly reasonable.

The best form of defense against these attacks is to alert employees to the risk of BEC scams. All employees with access to employee data should receive basic training to allow them to identify BEC scams. Email spam filters can be configured to block emails from spoofed domains, and policies implemented that require 2-factor authentication before any lists of employee data are sent via email. Policies can be implemented requiring secondary sign off before any lists of employee data are emailed.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist