According to Henry Ford Health's substitute notice, on 30 March 2023 an unauthorized party used an email phishing scheme to gain access to three employee business email accounts. On 16 May 2023 the organization determined protected health information may have been present in those mailboxes. Patient notices that followed cited roughly 168,215 people potentially exposed. Public reporting does not establish the phishing lure, what credential material was captured, whether MFA was present, or any MFA interaction.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did attackers access Henry Ford Health employee email?

The attackers accessed Henry Ford Health employee email through an email phishing scheme that produced unauthorized access to three employee business email accounts on 30 March 2023. That path is what the organization's substitute notice documents. Public reporting does not establish the lure text, whether a password alone was enough, or any second-factor step at sign-in.

How many patients were affected, and what data was at risk?

Henry Ford Health notices cited roughly 168,215 patients potentially exposed because PHI may have been present in the three compromised employee business email accounts. The organization reached that residual-mailbox determination on 16 May 2023, weeks after the March access, and patient notices went out around July 2023. Public reporting does not establish a separate break-in to an EHR or clinical system beyond content already sitting in those mailboxes.

Did MFA fail or get bypassed in the Henry Ford Health breach?

Public reporting does not establish whether MFA was enabled, absent, bypassed, or involved at all in the Henry Ford Health employee email phishing incident. The primary notice only states that an email phishing scheme led to unauthorized access to three employee business email accounts. Treating this as a proven MFA-bypass story invents a mechanism the disclosure never names.

Was the PHI exposure a live session problem or a deeper network compromise?

In the Henry Ford Health case, PHI risk was assessed as residual content inside three employee business email accounts the attacker already could open. That is post-sign-in data access from mailbox contents, not a separately documented ransomware event, ESXi wipe, or enterprise-wide token-theft campaign in the public notice. Once those mailboxes were open, no login control un-reads mail the attacker can already see.

What should workforce identity teams take from a three-mailbox healthcare phishing path?

The Henry Ford Health incident shows a tiny workforce mailbox footprint can still drive six-figure patient-notice exposure when ordinary business email holds clinical or billing content. The prevention conversation sits on the phishable employee email sign-in that opened the accounts. A fix for that login path exists; malware or local theft after a legitimate session is a harder, separate problem.