Cyber scam targets NBHH

By: 
John Bernhisel

Hospital reports fraudulent electronic transfers, patient info. remains secure

With so many positive indicators of growth at North Big Horn Hospital, new construction projects and new medical services being offered, it was extremely unwelcome news that the hospital was the victim of a social engineering cybercrime involving unauthorized bank transfers.

According to a statement released by the hospital, police reports and a subsequent interview with hospital CEO Eric Connell, an unknown bad actor gained unauthorized access to account information on May 28, resulting in fraudulent electronic transfers. On that date, a hospital employee with high-level access inadvertently gave information to a criminal posing as a member of the Bank of Lovell’s technology team.

The highly sophisticated scheme left the bank account open long enough for a large amount of money and some employee personal data to be stolen. The unnamed employee quickly notified the Lovell Police Department, which immediately passed the case to the Federal Bureau of Investigation because of the nature and amount of the crime.

Hospital officials said management immediately secured banking accounts, strengthened wire and ACH verification procedures and increased training for all employees with computer access.

Connell emphasized that no hospital patient data was ever in danger, and no personal patient information was compromised.

With the risk that some personal employee information may have been compromised, hospital employees were notified and took steps of their own to secure their finances.

The Lovell Police report indicates the scheme involved an individual posing as a trusted information technology contact at the Bank of Lovell who was able to trick a hospital employee into providing information that allowed access to a financial account.

“This was strictly a financial crime targeting a bank account,” Connell said in the hospital’s statement.

Right now, NBHH technology advisors and lawyers, as well as Bank of Lovell and Bank of Bridger employees, are doing everything possible to recover the money lost, Connell said. An insurance claim has been filed, and recovery efforts remain ongoing.

Connell emphasized that, with all the ongoing efforts for recovery, it would be premature to give an amount of the loss until every possible process was completed. Even if the full six-figure amount (initially $659,000) is ultimately unrecoverable, it would not affect in any way the ability of NBHH to provide the excellent medical services it offers, alter its plans for the future or force the hospital to raise rates, which have not changed in more than two years, Connell said.

A Bank of Lovell officer said the bank could not provide any details of the incident from the bank’s end, citing privacy issues regarding the customer.

Cybersecurity experts across the personal and business technology world continue to warn that social engineering attacks like this one are becoming increasingly common and often rely on impersonation and deception rather than traditional computer hacking methods. Be extremely cautious about providing information or granting access over the phone, and visit your bank’s offices whenever there are questions.

Category: