Supply chain ⛓ Supply Chain

Department of Health and Human Services,UChicago, King's Daughters' Health System, OSF HealthCare, Aspirus, UChicago Medicine, and Memorial Hermann Health System. Third-Party Breach (April 2021)

📅 2021-04-01 🏢 MedData
Primary Source ↗

Incident Details

Patient Data from Multiple Providers Leaked in Third-Party GitHub Incident | TechTarget. Data breach notifications and a report reveal a former MedData employee uploaded troves of patient data from multiple providers onto the open-source, public data repository GitHub Arctic Code Vault. The patient data from multiple providers appears to have been captured and subsequently leaked on the data repository GitHub Arctic Code Vault by third-party vendor MedData, according to a new collaborative report from security researcher Jelle Ursem and Dissent Doe of DataBreaches.net. MedData provides revenue cycle services to healthcare systems and hospitals, including Medicaid eligibility, third-party liability, workers’ compensation, and patient billing services. Third-party company: MedData.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
MedData
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2021-04-01 Breach occurred
  2. 2021-04-02 Publicly disclosed