Monongalia County General Hospital Company (Mon General) was the victim of a phishing attack that may have resulted in unauthorized access to personal information of some of its patients.
On May 6, 2026, Mon General discovered that a small number of email users were the subject of a phishing attack. It promptly began investigating this incident with the assistance of a respected forensic security provider and took steps to terminate any unauthorized access to Mon General’s email.
Its investigation, which concluded in late June 2026, ultimately determined that an unauthorized party gained access to certain Mon General email mailboxes on May 6, 2026, and the unauthorized access was terminated on the same day. No other Mon General systems or data storage were impacted by this incident.
The information that may have been impacted varied from person to person but may have included: first and last name; date of birth; e-mail address; phone number; Social Security number; health information, and health insurance information.
Following the incident, Mon General worked with external cybersecurity experts to resolve the phishing attack. Mon General reset user credentials and is regularly evaluating how to augment its existing technical safeguards.
Building Around Care: Lessons in Modernizing Active Healthcare Environments
St. Luke's Heart Hospital Opens at Anderson Campus in Pennsylvania
WindRose Health Network Ensnared in Vendor Data Breach
How Efficiency Checklists Help Hospitals Save Energy, Water and Money
Intermountain Healthcare Receives $50M Gift for Standalone Children's Hospital