Supply chain
⛓ Supply Chain
QRS Clients Third-Party Breach (November 2021)
Primary Source ↗Incident Details
320K Impacted in EHR Vendor Breach, Ransomware Hits Health Systems | TechTarget. Unauthorized email access and ransomware disrupted the operations of other health systems, while nn EHR vendor breach exposed the PHI of 320K. An EHR vendor began notifying its clients of a data breach that may have exposed the personally identifiable information (PII) and protected health information (PHI) of nearly 320,000 individuals. Other recent data breaches involved unauthorized email access and ransomware. Ransomware continues to be one of healthcare’s biggest cyber threats to date. The US Department of State recently offered a reward of up to $10 million for information leading to the identification of key leadership in the DarkSide ransomware group. DarkSide claimed responsibility for the Colonial Pipeline attack in May, which pushed ransomware to the top of the White House’s priority list. Third-party company: QRS.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- QRS
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2021-11-01 Breach occurred
- 2021-11-09 Publicly disclosed