Supply chain β›“ Supply Chain

Fox's clinic, the Alpine Center for Diabetes, Endocrinology and Metabolism Third-Party Breach (May 2021)

πŸ“… 2021-05-01 🏒 APRIMA
Primary Source β†—

Incident Details

Reported ransomware attack leads to weeks of Aprima EHR outages. Some customers describe being unable to access their clinic schedules, chart notes, refill requests or incoming test results, among other issues. [This piece has been updated to include additional user experiences with the outage.]. A reported ransomware attack on the CompuGroup Medical data center partner, MedNetwoRX, has impeded some customers’ access to their Aprima electronic health record systems for more than two weeks. Third-party company: APRIMA.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
APRIMA
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2021-05-01 Breach occurred
  2. 2021-05-01 Publicly disclosed