Supply chain ⛓ Supply Chain

Beaumont Health Third-Party Breach (February 2021)

📅 2021-02-01 🏢 Epic Software
Primary Source ↗

Incident Details

Actor Exploits Beaumont Health’s COVID-19 Vaccine Scheduling Tool | TechTarget. This week's breach roundup is led by a Beaumont Health security incident. An actor exploited a flaw in Epic's scheduling tool, which allowed 2,700 people to make unauthorized COVID-19 vaccine appts. Michigan-based Beaumont Health was forced to shut down its tool for scheduling COVID-19 vaccine appointments over the weekend, after an unauthorized actor exploited a flaw in the Epic platform. The act allowed 2,700 people to cut in line and register for unauthorized appointments. Third-party company: Epic Software.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Epic Software
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2021-02-01 Breach occurred
  2. 2021-02-02 Publicly disclosed