Supply chain
⛓ Supply Chain
Department of Health and Human Services,UChicago, King's Daughters' Health System, OSF HealthCare, Aspirus, UChicago Medicine, and Memorial Hermann Health System. Third-Party Breach (April 2021)
Primary Source ↗Incident Details
Patient Data from Multiple Providers Leaked in Third-Party GitHub Incident | TechTarget. Data breach notifications and a report reveal a former MedData employee uploaded troves of patient data from multiple providers onto the open-source, public data repository GitHub Arctic Code Vault. The patient data from multiple providers appears to have been captured and subsequently leaked on the data repository GitHub Arctic Code Vault by third-party vendor MedData, according to a new collaborative report from security researcher Jelle Ursem and Dissent Doe of DataBreaches.net. MedData provides revenue cycle services to healthcare systems and hospitals, including Medicaid eligibility, third-party liability, workers’ compensation, and patient billing services. Third-party company: MedData.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- MedData
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2021-04-01 Breach occurred
- 2021-04-02 Publicly disclosed