Supply chain
⛓ Supply Chain
AC Health Systems and San Diego Family Care (SDFC), CareSouth Carolina, Health Center Partners of Southern California Third-Party Breach (May 2021)
Primary Source ↗Incident Details
Ransomware Hits Scripps Health, Disrupting Critical Care, Online Portal | TechTarget. This week's breach roundup is led by a ransomware attack on Scripps Health. The cyberattack over the weekend has resulted in EHR downtime procedures and the diversion of trauma patients. Scripps Health in San Diego was hit by a ransomware attack over the weekend, forcing the health system into EHR downtime. Some critical care patients were diverted and the online patient portal has been taken offline, according to local news outlet San Diego Union-Tribune. Monday appointments were also postponed due to the cyberattack, which disrupted operations at two of Scripps’ four main hospitals and backup servers that reside in Arizona. Providers and other clinicians are leveraging paper records, as telemetry has been impacted at most care sites. Access to medical imaging also appears to be down. Third-party company: Netgain.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Netgain
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2021-05-01 Breach occurred
- 2021-05-03 Publicly disclosed