Skip to main content
Back
Silver Creek Fitness & Physical Therapy

Silver Creek Fitness & Physical Therapy Data Breach (2016)

Silver Creek Fitness & Physical Therapy

lowVERIS
Disclosed

January 1, 2016

3738 days ago

Records

Undisclosed

Confirmed

Root Cause

Misconfiguration

Industry

Healthcare

Description

On September 11, 2016, Silver Creek was notified by its billing and software companies that its Amazon "S3" storage account was vulnerable because it was accessible to persons outside their organization, and that a security researcher who works for a software company accessed and downloaded information from the storage account. This storage account contained, among other things, protected health information of certain Silver Creek Fitness & Physical Therapy patients. The billing and software companies immediately took steps to secure the storage account and launched an investigation to determine to what extent sensitive information was accessed or acquired. They determined that the storage account was vulnerable from May, 2016 to September 11, 2016 and that information was accessed and downloaded by the security researcher on or around September 10, 2016.