The Hawaii Department of Health (DOH) has started sending out notifications about a data breach resulting in the compromise of roughly 3,400 death records.
In January, the DOH says, it was informed that an external medical certifier account on the DOH Electronic Death Registry System (EDRS) was compromised and that the associated login credentials were being traded on hacker forums.
According to DOH, “the account belonged to a medical certifier at a local hospital who had left employment in June 2021, but whose account had not been deactivated.”
Using the compromised credentials, threat actors accessed the EDRS in January 2023 and accessed roughly 3,400 death records with dates of death ranging between 1998 and 2023.
Most of the deaths occurred in 2014 or earlier, and almost all of them had been certified before the intrusion. For those that had not been certified, DOH’s investigation found no evidence of tampering.
Information included in those records includes names, addresses, birth dates, sex, dates and places of death, cause of death, and Social Security numbers.
“No death certificates were accessed, nor were any able to be generated. However, out of an abundance of caution, DOH encourages affected parties to remain vigilant about any remaining unsettled matters such as accounts, estate, life insurance claim or Social Security survivor benefits,” DOH says.
The department is sending notification letters to surviving spouses or those individuals who reported the death to the mortuary.
Related: Zoll Medical Data Breach Impacts 1 Million Individuals
Related: Congress Members Warned of Significant Health Data Breach
Related: Patient Information Compromised in Data Breach at San Diego Healthcare Provider
Related: Data Breach at Louisiana Healthcare Provider Impacts 270,000 Patients

More from Ionut Arghire
- Ransomware Gang Publishes Data Allegedly Stolen From Maritime Firm Royal Dirkzwager
- Zoom Paid Out $3.9 Million in Bug Bounties in 2022
- Malicious NuGet Packages Used to Target .NET Developers
- Google Pixel Vulnerability Allows Recovery of Cropped Screenshots
- Millions Stolen in Hack at Cryptocurrency ATM Manufacturer General Bytes
- NBA Notifying Individuals of Data Breach at Mailing Services Provider
- Adobe Acrobat Sign Abused to Distribute Malware
- Latitude Financial Services Data Breach Impacts 300,000 Customers
Latest News
- Google Suspends Chinese Shopping App Amid Security Concerns
- Verosint Launches Account Fraud Detection and Prevention Platform
- Ransomware Gang Publishes Data Allegedly Stolen From Maritime Firm Royal Dirkzwager
- Zoom Paid Out $3.9 Million in Bug Bounties in 2022
- Oleria Scores $8M Seed Funding for ID Authentication Technology
- Exploitation of 55 Zero-Day Vulnerabilities Came to Light in 2022: Mandiant
- News Analysis: UK Commits $3 Billion to Support National Quantum Strategy
- Malicious NuGet Packages Used to Target .NET Developers
