Harris Health, a major healthcare provider in Texas, is notifying 5,000 patients about a significant insider data breach that persisted for over ten years. The breach involved a former employee who accessed electronic health records (EHRs) without a legitimate work-related reason from January 4, 2011, to March 8, 2021. The organization discovered the unauthorized access on February 10, 2021, and immediately launched an internal investigation with the assistance of a forensic firm. Upon confirming the breach, Harris Health reported the incident to the FBI and terminated the employee responsible for the unauthorized access. The investigation revealed that the former employee had disclosed some patient information to unauthorized individuals, raising concerns about the potential misuse of sensitive health data. Due to the ongoing FBI investigation, Harris Health was required by law enforcement to delay notifying affected patients until it would not impede the inquiry. Only after receiving explicit clearance from the FBI was Harris Health able to begin the notification process. The breach affected patients across Harris Health’s extensive network, which includes two trauma center hospitals and 37 clinics, health centers, and specialty locations. The organization emphasized that it is now notifying patients as quickly as possible following the law enforcement directive. The breach notification process is part of Harris Health’s compliance with data security and privacy regulations, and the organization has reiterated its commitment to protecting patient information. The incident highlights the risks posed by insider threats within healthcare organizations, especially given the long duration of undetected access. Harris Health has not been able to determine which specific sensitive information was disclosed in every case, but the potential exposure includes personal and medical data. The organization’s response included collaboration with law enforcement and external forensic experts to assess the scope and impact of the breach. The case underscores the importance of robust monitoring and access controls for EHR systems to prevent and detect unauthorized activity. Harris Health’s experience serves as a cautionary example for other healthcare entities regarding the need for vigilance against insider threats. The breach has prompted a review of internal security policies and procedures to mitigate the risk of similar incidents in the future. The FBI’s involvement and the protracted nature of the investigation demonstrate the complexity of insider breaches in the healthcare sector.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
GovInfoSecurity and BankInfoSecurity reported that a hospital insider breach had lasted 10 years and had led to an FBI inquiry. No additional dated milestones or technical details were provided in the reference content.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.