Skip to main content
Back to overview
High

Atrium Health Notifies 585,000 Individuals of Data Exposure Related to Online Tracking Technologies

Healthcare company Atrium Health has notified the US Department of Health and Human Services (HHS) that a recently discovered data breach impacts more than 585,000 individuals.

Key points

  • Atrium Health notified HHS on December 6, 2024, about a data breach affecting 585,000 individuals.
  • The incident involved online tracking technologies on patient portals (2015-2019).
  • Personal information may have been transmitted to third-party vendors (Google, Facebook).

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Social, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Dec 6, 2024
Updated
Jul 22, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking, Error activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

AtriumhealthData DisclosureAtrium Health NotifiesOnline Tracking Technologies HealthcareAtrium HealthUS Department of Health andHuman ServicesHHSThe HHSThese

Quick context

Questions about this signal

What happened in this signal?

Healthcare company Atrium Health has notified the US Department of Health and Human Services (HHS) that a recently discovered data breach impacts more than 585,000 individuals. The HHS website does not provide any information regarding the incident, but the notification is likely related to an issue involving online tracking technologies that were present on an Atrium Health patient portal between 2015 and 2019.  “These commonly used internet technologies were utilized to help operate certain features of our Patient Portal and enhance the online experience for users. We have learned that, during this time frame, these technologies may have transmitted certain personal information to third-party vendors, such as Google and Facebook (now Meta),” Atrium told impacted individuals recently. The company said an initial review of the tracking technologies, conducted in 2022, did not uncover any issues, but a more recent analysis of online technologies on the patient portal did reveal the possible exposure of information. Atrium said it’s difficult to precisely determine what data was transmitted to third-parties, but it’s assuming that all users of the MyAtriumHealth or MyCarolinas patient portal between January 2015 and July 2019 are affected.  Depending on the user’s browser, configuration, and actions, information such as IPs, cookies, information on treatment or provider, names, email addresses, phone numbers, and physical addresses may have been exposed. Advertisement. Scroll to continue reading. “Based on our review, no Social Security number, financial account, credit card or debit card information was involved,” Atrium pointed out, adding, “There is no evidence that any information that may have been shared with these third parties has been misused in any way. Moreover, the nature of the information that could have been collected would be very unlikely to result in identity theft or any financial harm.” It’s worth noting that this is not the only cybersecurity incident disclosed by Atrium in recent months. In mid-September, the company notified a subset of patients and employees after discovering that over a period of two days in April someone had gained access to employee email accounts through phishing.  An investigation showed that the compromised email accounts stored information on some patients and employees, including a wide range of personal, financial and health information, such as Social Security numbers, bank account information, access credentials, and treatment/diagnosis details. SecurityWeek has reached out to Atrium Health for clarifications regarding which of these incidents impacted 585,000 people, but the healthcare company has not responded. Atrium Health provides healthcare services at more than 1,400 care locations and 40 hospitals across several states. Back in 2018, Atrium Health experienced a data breach that impacted 2.6 million patients.  Update 12.09.2024: Atrium Health has confirmed for SecurityWeek that the incident impacting 585,000 people is the one involving online tracking technologies. Related : Other healthcare data breaches covered by SecurityWeek Related : Two UK Hospitals Hit by Cyberattacks, One Postponed Procedures Related : Bipartisan Legislation Seeks Stronger Healthcare Cybersecurity Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains

When was this signal reported?

Shadow Tier lists Dec 6, 2024 as the signal date.

Which organization is connected to this signal?

Atriumhealth is the organization connected to this public signal.

Explore Atriumhealth
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence