Data leak
β Supply Chain
HIPAA Journal
Primary Source βIncident Details
Perry Johnson & Associates (PJ&A), a Nevada-based medical transcription services company, was breached between March 27 and May 2, 2023. The breach went undetected for over a month, and PJ&A did not notify downstream clients until November 2023, six months after discovery. At least 14 million total patients were affected across PJ&A clients. Concentra Health Services confirmed 3,998,163 of its patients were affected. Additional major victims included Cook County Health (~1.2 million patients) and Northwell Health (~3.9 million patients). Stolen data included names, dates of birth, addresses, medical record numbers, admission diagnoses, lab/diagnostic testing results, medications, and for some individuals Social Security numbers and insurance information.
Technical Details
- Initial Attack Vector
- CWE-284: Improper Access Control
- Vendor / Product
- Perry Johnson & Associates (PJ&A) medical transcription platform
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-03-27 Breach occurred
- 2023-11-01 Publicly disclosed
- 2024-02-01 Customers notified