Supply chain β›“ Supply Chain

Anthem, Humana Third-Party Breach (October 2021)

πŸ“… 2021-10-01 🏒 PracticeMax
Primary Source β†—

Incident Details

Third-Party Vendor Ransomware Attack Impacts Humana, Anthem Members | TechTarget. PracticeMax, a billing and IT solutions provider, experienced a ransomware attack that impacted some Humana and Anthem members. Both Humana and Anthem began notifying members that their protected health information (PHI) had been exposed following a ransomware attack on billing and IT solutions vendor PracticeMax. Humana and Anthem use PracticeMax to share information with Village Health, a provider that helps patients with end-stage kidney disease. Village Health provides care coordination between dialysis centers, providers, and nephrologists. Humana stated that over 4,000 patients were impacted, and it remains unclear how many Anthem members were exposed. Third-party company: PracticeMax.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
PracticeMax
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2021-10-01 Breach occurred
  2. 2021-10-27 Publicly disclosed