Tosoh America, Inc. Data Breach
Tosoh America Email Breach Affects 880 Patients in Ohio
What happened in the Tosoh America, Inc. data breach?
The Tosoh America, Inc. data breach was reported on June 17, 2022 and affected 880 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Ohio. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Tosoh America, Inc. Breach Details
Tosoh America, Inc. Healthcare Data Breach Report
Incident Overview
Tosoh America, Inc., a healthcare-related organization based in Ohio, experienced a significant data breach involving unauthorized access to its email systems. The breach was discovered and reported to the U.S. Department of Health and Human Services on June 17, 2022, affecting approximately 880 individuals. The unauthorized access to email systems represents a common but serious vulnerability in healthcare IT infrastructure, as email accounts frequently contain sensitive patient health information, demographic data, and other protected health information (PHI) that may be transmitted or stored within email clients and servers.
Discovery and Response Timeline
The specific discovery date and investigation timeline for this breach were not detailed in the initial notification submission, though the June 17, 2022 submission date indicates the breach was reported to HHS within the required 60-day notification window mandated by HIPAA Breach Notification Rule. Upon discovery of the unauthorized email access, Tosoh America initiated an investigation to determine the scope of the breach, identify which patient records were accessed, and assess what types of information may have been compromised. The organization subsequently notified affected individuals as required by HIPAA regulations, providing details about the breach and recommended protective measures. No business associate involvement was noted in this incident, indicating the breach occurred within Tosoh America's own systems and infrastructure.
Technical Details of the Email Breach
Breach Vector and Method
Email system breaches typically occur through several common attack vectors. Hacking incidents targeting email infrastructure may involve credential compromise (stolen usernames and passwords), exploitation of unpatched email server vulnerabilities, phishing attacks that compromise employee credentials, or direct unauthorized access to email servers. Email systems are particularly attractive targets for threat actors because they often contain a concentrated repository of sensitive information and may lack the same level of security controls as dedicated healthcare databases. Once an attacker gains access to an email account or email server, they can potentially access years of historical correspondence containing patient information, clinical notes, appointment details, and other sensitive communications.
The location designation of "Email" in this breach indicates that the primary point of compromise was the email system itself, rather than a centralized database or network server. This suggests that either individual email accounts were compromised, or the email server infrastructure was accessed without authorization. Email breaches of this nature typically expose whatever information was stored in email folders, including sent items, received messages, attachments, and potentially archived communications.
Organizational Context
Tosoh America, Inc. is a healthcare-related organization operating in Ohio. Based on the nature of the breach affecting patient health information, the organization likely provides healthcare services, diagnostic testing, laboratory services, or related healthcare operations. The organization's operations in Ohio and the notification of 880 affected individuals suggest a regional healthcare provider or service organization with patient populations across the state. The fact that this breach involved patient health information indicates Tosoh America is a HIPAA-covered entity subject to federal privacy and security regulations.
Impact on Affected Individuals
Number of People Affected
Approximately 880 individuals were affected by this breach of Tosoh America's email systems. While this number falls below the 1,000-individual threshold for some reporting categories, the breach still represents a significant exposure of patient information and required notification to each affected individual as well as reporting to HHS and potentially to Ohio state authorities.
Patient Notification
Under HIPAA's Breach Notification Rule, Tosoh America was required to notify each affected individual without unreasonable delay and in no case later than 60 calendar days after discovery of the breach. The June 17, 2022 HHS submission date indicates the organization met this notification requirement. Affected individuals should have received written notification describing the nature of the breach, the types of information exposed, steps the organization is taking to investigate and remediate the breach, and recommended actions patients should take to protect themselves.
Likely Data Exposure
Personal Information Involved
Given that the breach involved email systems at a healthcare organization, the following types of protected health information may have been exposed:
- Patient Names and Contact Information: Email communications typically include sender and recipient names, email addresses, phone numbers, and mailing addresses
- Medical Record Numbers and Patient Identifiers: Healthcare-related emails frequently reference patient identification numbers used in medical records systems
- Clinical Information: Depending on the nature of communications, emails may contain clinical notes, test results, diagnoses, treatment plans, or other clinical information
- Insurance Information: Emails may reference insurance carriers, policy numbers, or coverage details
- Appointment and Scheduling Information: Details about patient appointments, procedures, or healthcare visits
- Demographic Information: Age, date of birth, gender, and other demographic identifiers
- Health History: Information about past medical conditions, medications, allergies, or treatment history
The specific types of information exposed would depend on what information was included in the compromised email accounts and what communications had been stored in the email system.
Risks to Patients
The unauthorized access to email systems containing patient health information creates several specific risks:
Identity Theft Risk: Exposure of names, dates of birth, and other demographic information combined with any financial or insurance details creates risk for identity theft and fraudulent account creation.
Medical Identity Theft: Criminals may use exposed health information to obtain medical services, prescription medications, or medical equipment under a patient's name, potentially creating false medical records or insurance claims.
Phishing and Social Engineering: Threat actors with access to patient email addresses and health information may use this data to craft convincing phishing emails or social engineering attacks targeting patients.
Insurance Fraud: Exposure of insurance information combined with health data could enable fraudulent insurance claims or coverage manipulation.
Privacy Violation: Unauthorized access to personal health information and private communications represents a violation of patient privacy and confidentiality expectations.
Reputational Harm: Patients may experience concern or distress from knowing their sensitive health information was accessed without authorization.
HIPAA Compliance Context
This breach represents a failure of Tosoh America's administrative, physical, and technical safeguards as required under the HIPAA Security Rule. Healthcare organizations are required to implement and maintain security measures to protect electronic protected health information (ePHI) from unauthorized access, including:
- Access controls and authentication mechanisms
- Encryption of data in transit and at rest
- Regular security assessments and vulnerability testing
- Employee training on security and privacy
- Incident response procedures
- Audit controls and monitoring
Email system breaches are among the most common causes of healthcare data breaches, accounting for a significant percentage of reported incidents annually. The prevalence of email-based breaches has led to increased regulatory focus on email security, including requirements for multi-factor authentication, encryption, and advanced threat detection.
Recommended Actions for Patients
Individuals affected by this breach should take the following protective measures:
-
Monitor Credit Reports: Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and review for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus.
-
Monitor Healthcare Accounts and Explanation of Benefits: Review all healthcare-related bills, explanation of benefits statements, and medical records for unauthorized services, treatments, or claims. Contact healthcare providers immediately if suspicious activity is identified.
-
Change Passwords and Enable Multi-Factor Authentication: If you have online accounts with Tosoh America or related healthcare providers, change passwords to strong, unique credentials and enable multi-factor authentication where available.
-
Be Alert to Phishing and Social Engineering: Be cautious of unsolicited emails, phone calls, or messages claiming to be from healthcare providers or requesting personal information. Do not click links or download attachments from suspicious sources, and verify requests by contacting organizations directly using known contact information.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Tosoh America, Inc. Breach
Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and monitor for unauthorized accounts, inquiries, or suspicious activity. Consider placing a fraud alert or credit freeze to prevent unauthorized credit applications.
Review all healthcare bills, explanation of benefits statements, and medical records for unauthorized services, treatments, or claims. Contact Tosoh America and your healthcare providers immediately if you identify any suspicious activity or services you did not receive.
Change passwords for any online accounts with Tosoh America or related healthcare providers to strong, unique credentials and enable multi-factor authentication where available to prevent unauthorized account access.
Remain vigilant against phishing emails, suspicious phone calls, and social engineering attempts. Do not click links or download attachments from unsolicited messages claiming to be from healthcare providers. Verify requests by contacting organizations directly using known contact information from official websites or previous statements.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Ohio Breaches
Search all breaches reported in Ohio