On 20 April 2021, phishing compromised a limited number of employee email accounts at Children’s Hospital of The King’s Daughters (CHKD) in Norfolk, Virginia. According to HIPAA Journal, attackers could read mail and attachments holding PHI for some CHKD patients and guarantors, certain Sentara Norfolk General Hospital lab and diagnostic patients, and some student athletes. Public reporting does not name AiTM kits, device-code flows, helpdesk recovery, or a threat actor, and it does not state whether those mailboxes required MFA.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did attackers get into CHKD employee email?

Attackers got into CHKD employee email by phishing that compromised a limited number of Children’s Hospital of The King’s Daughters workforce mailboxes on 20 April 2021. According to HIPAA Journal, that access was enough to view messages and attachments. Public reporting does not establish reverse-proxy AiTM pages, stolen session cookies as the stated vector, OAuth device-code phishing, or a helpdesk password reset. The confirmed story stops at classic credential-phase email phishing against employees.

What PHI was exposed in the CHKD phishing incident?

In the CHKD employee email phishing incident, exposed data included protected health information for some CHKD patients and guarantors, certain Sentara Norfolk General Hospital lab and diagnostic patients, and some student athletes receiving athletic training services. Types varied by person and could include full name, date of birth, patient account number, health insurance number, and/or other health-related information, with Social Security numbers for a limited number of people. Public reporting does not establish an exact count of affected individuals. CHKD said no evidence suggested the information had been or would be misused, and offered credit monitoring where SSNs were exposed.

Was MFA bypassed at CHKD?

Public reporting does not establish whether MFA was enabled, disabled, or challenged on the CHKD employee mailboxes that were phished, so “MFA bypassed” is not a supported claim. What is supported is that phishing produced usable access to a small number of workforce email accounts. After those accounts were open, reading inbox content was ordinary mailbox use, not a second login ceremony.

Did stronger login controls still matter after the mailboxes were open?

Closing a phishable employee email login stops the account-takeover path that opened the CHKD mailboxes in the first place. Once those accounts were already compromised, no MFA undoes reading of mail and attachments the mailbox owner could already see. CHKD later said additional anti-phishing measures were being implemented; public notices still leave the original login-factor mix unnamed. A fix for phishable workforce login factors exists; the prevention write-up is on the companion site.

What is the public timeline for the CHKD breach?

CHKD’s disclosed timeline puts the phishing compromise on 20 April 2021. Upon discovery, the email environment was secured and third-party forensics experts were engaged. Full scope of unauthorized access was determined by 11 June 2021, details of affected individuals arrived by 12 July 2021, and patient notification went out on 10 August 2021. Public reporting does not establish the exact calendar date of first discovery between the April compromise and the June scope review.