Polsinelli PC Data Breach
Polsinelli PC Network Server Breach Affects 1,220
What happened in the Polsinelli PC data breach?
The Polsinelli PC data breach was reported on December 2, 2022 and affected 1,220 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Missouri. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Polsinelli PC Breach Details
Polsinelli PC Network Server Security Incident
Polsinelli PC, a prominent law firm headquartered in Missouri, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to affected individuals in December 2022, affecting approximately 1,220 individuals whose protected health information (PHI) may have been accessed or compromised. As a business associate to healthcare entities, Polsinelli PC maintains sensitive patient data as part of its legal services and healthcare consulting operations. The unauthorized access to the network server represents a serious breach of the security safeguards required under the Health Insurance Portability and Accountability Act (HIPAA) and its associated Security Rule.
Company Response
Upon discovery of the unauthorized access to its network server, Polsinelli PC initiated a comprehensive investigation to determine the scope and nature of the breach. The firm engaged forensic specialists to analyze the compromised systems, identify the attack vector, and assess what information may have been accessed by unauthorized parties. The investigation and notification process culminated in the breach being reported to the Department of Health and Human Services (HHS) on December 2, 2022, meeting the HIPAA requirement to notify affected individuals without unreasonable delay and no later than 60 calendar days following discovery of a breach of unsecured PHI. Polsinelli PC provided notification to all 1,220 affected individuals regarding the incident and offered guidance on protective measures.
Specific Details
The breach occurred on Polsinelli PC's network server infrastructure, which typically represents a centralized repository of client and patient information accessed across the organization's operations. Network server breaches of this nature are commonly attributed to exploitation of unpatched software vulnerabilities, weak authentication credentials, compromised remote access credentials, or targeted cyberattacks against the organization's perimeter defenses. The fact that the breach affected a network server—rather than isolated workstations or portable devices—suggests the potential for broad exposure across multiple data categories and client matters. Hackers targeting law firms and business associates often seek to access sensitive healthcare information, financial records, and confidential client communications that can be leveraged for fraud, identity theft, or competitive advantage. The network location of the breach indicates that the unauthorized access may have persisted for an indeterminate period before detection, potentially allowing threat actors to exfiltrate data or establish persistent access mechanisms.
Organizational Context
Polsinelli PC is a national law firm with significant healthcare law and consulting practices, serving healthcare providers, health plans, and related entities across multiple states. As a business associate under HIPAA, the firm handles protected health information on behalf of its healthcare clients and is contractually obligated to maintain appropriate administrative, physical, and technical safeguards to protect that information. The firm's operations span multiple offices and service lines, including healthcare regulatory compliance, litigation support, and business consulting. The breach's impact on a network server suggests that the compromised infrastructure may have supported multiple practice areas and client relationships, potentially affecting individuals whose information was stored in connection with various healthcare matters and client engagements.
Number of People Affected
Approximately 1,220 individuals were notified of the breach, representing patients, clients, or individuals whose health information was maintained within Polsinelli PC's systems. This figure places the breach in the medium-severity category in terms of scale, though the sensitivity of the data involved elevates the overall risk profile. The affected population likely includes individuals whose information was associated with healthcare clients served by the firm, spanning potentially multiple healthcare organizations and jurisdictions. The notification to 1,220 individuals suggests that the unauthorized access affected a substantial portion of the firm's active healthcare-related data holdings.
Personal Information Involved
While the specific data elements exposed in the breach were not detailed in the public filing, individuals affected by breaches of law firm network servers typically face exposure of:
- Full names and contact information (addresses, phone numbers, email addresses)
- Social Security numbers or tax identification numbers
- Date of birth and demographic information
- Health insurance information and policy numbers
- Medical record numbers and healthcare provider identifiers
- Diagnosis codes, treatment information, and clinical notes
- Financial account information and banking details
- Insurance claim information and payment records
- Legal matter details and confidential communications
- Government-issued identification numbers
The breadth of information potentially exposed reflects the comprehensive nature of data typically maintained by healthcare law firms and business associates in the course of their operations.
Likely Risks to Patients
Individuals affected by this breach face several significant risks stemming from the unauthorized access to their protected health information:
Identity Theft and Fraud: Exposure of Social Security numbers, dates of birth, and financial information creates substantial risk for identity theft, fraudulent account creation, and financial fraud. Threat actors may use this information to open credit accounts, obtain loans, or conduct other fraudulent transactions in victims' names.
Medical Identity Theft: Access to health insurance information, medical record numbers, and clinical details enables medical identity theft, where perpetrators use victims' identities to obtain healthcare services, prescription medications, or medical equipment, potentially resulting in fraudulent charges and contaminated medical records.
Insurance Fraud: Exposure of insurance policy numbers and claim information may facilitate fraudulent insurance claims or policy manipulation.
Targeted Phishing and Social Engineering: Threat actors may use exposed personal information to craft convincing phishing emails or social engineering attacks targeting victims, potentially leading to credential compromise or malware infection.
Privacy Violations: The unauthorized access to sensitive health information and confidential legal matters represents a serious violation of privacy expectations and may cause emotional distress and reputational harm.
Long-term Surveillance Risk: Information obtained from network server breaches may be retained and used for ongoing targeting or exploitation over extended periods.
Recommended Actions for Patients
-
Monitor Credit Reports: Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and review for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
-
Implement Identity Theft Monitoring: Enroll in credit monitoring and identity theft protection services, which Polsinelli PC likely offered as part of breach remediation. Monitor accounts for suspicious activity and consider using identity theft protection services that provide alerts for unauthorized use of personal information.
-
Secure Financial Accounts: Change passwords for all financial accounts, healthcare portals, and insurance accounts to strong, unique credentials. Enable multi-factor authentication where available and monitor accounts for unauthorized transactions or access attempts.
-
File Fraud Reports if Needed: If you discover fraudulent activity or unauthorized use of your information, file a report with the Federal Trade Commission (FTC) at IdentityTheft.gov and contact your financial institutions and healthcare providers immediately to dispute fraudulent charges and correct medical records.
Severity Assessment
This breach is classified as medium severity based on the following factors:
- Scale: 1,220 affected individuals falls within the medium range (1,000-10,000)
- Data Sensitivity: Network server breaches typically expose multiple categories of sensitive PHI including SSNs, financial information, and clinical data
- Breach Type: Hacking/IT incidents targeting network infrastructure typically indicate sophisticated threat actors with potential for data exfiltration and misuse
- Business Associate Status: The involvement of a business associate means the breach affects healthcare data subject to HIPAA's strictest protections
While the number of affected individuals is not in the highest category, the likely sensitivity of data exposed and the network-wide nature of the compromise elevate the risk profile above low-severity incidents.
Visibility Assessment
This breach is classified as regional visibility based on:
- Polsinelli PC's multi-state operations and national law firm status
- The involvement of healthcare clients across multiple jurisdictions
- The 1,220 affected individuals potentially spanning multiple states
- The breach's impact on a business associate serving healthcare entities across a broad geographic area
Technical Notes
Network server breaches typically result from one or more of the following attack vectors:
- Unpatched Vulnerabilities: Exploitation of known security vulnerabilities in server operating systems, web applications, or network services that have not been patched
- Weak Authentication: Compromise of administrative credentials through brute force attacks, credential stuffing, or phishing
- Remote Access Exploitation: Abuse of remote desktop services (RDP), VPN access, or other remote connectivity mechanisms with weak or compromised credentials
- Ransomware/Malware: Deployment of malware that establishes persistent access and exfiltrates data
- Insider Threats: Unauthorized access by employees or contractors with legitimate system access
- Supply Chain Compromise: Exploitation of vulnerabilities in third-party software or services integrated with the network
Network server breaches are particularly concerning because they typically affect centralized data repositories, potentially exposing information across multiple client matters and business functions simultaneously. The investigation and remediation of such breaches requires comprehensive forensic analysis, system hardening, and implementation of enhanced security controls to prevent recurrence.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Polsinelli PC Breach
Monitor your credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) by obtaining free annual reports at AnnualCreditReport.com. Review reports carefully for unauthorized accounts, inquiries, or suspicious activity. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications in your name.
Enroll in credit monitoring and identity theft protection services, which Polsinelli PC likely offered as part of breach remediation. Monitor accounts for suspicious activity, set up fraud alerts on financial accounts, and consider using identity theft protection services that provide real-time alerts for unauthorized use of your personal information.
Change passwords for all financial accounts, healthcare portals, insurance accounts, and email accounts to strong, unique credentials. Enable multi-factor authentication (MFA) wherever available. Monitor all accounts regularly for unauthorized transactions, access attempts, or suspicious activity.
If you discover fraudulent activity or unauthorized use of your information, file a report immediately with the Federal Trade Commission (FTC) at IdentityTheft.gov, contact your financial institutions and healthcare providers to dispute fraudulent charges, and request correction of any inaccurate information in your medical records and credit files.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Missouri Breaches
Search all breaches reported in Missouri