Supply chain ⛓ Supply Chain

QRS Clients Third-Party Breach (November 2021)

📅 2021-11-01 🏢 QRS
Primary Source ↗

Incident Details

320K Impacted in EHR Vendor Breach, Ransomware Hits Health Systems | TechTarget. Unauthorized email access and ransomware disrupted the operations of other health systems, while nn EHR vendor breach exposed the PHI of 320K. An EHR vendor began notifying its clients of a data breach that may have exposed the personally identifiable information (PII) and protected health information (PHI) of nearly 320,000 individuals. Other recent data breaches involved unauthorized email access and ransomware. Ransomware continues to be one of healthcare’s biggest cyber threats to date. The US Department of State recently offered a reward of up to $10 million for information leading to the identification of key leadership in the DarkSide ransomware group. DarkSide claimed responsibility for the Colonial Pipeline attack in May, which pushed ransomware to the top of the White House’s priority list. Third-party company: QRS.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
QRS
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2021-11-01 Breach occurred
  2. 2021-11-09 Publicly disclosed