Supply chain
⛓ Supply Chain
Ciox Health Third-Party Breach — Baptist Memorial, Children's Healthcare of Atlanta, Hoag, 28+ Health Systems
Primary Source ↗Incident Details
In January 2022, Ciox Health — a major provider of health information management (HIM) services including medi
cal record retrieval, release-of-information (ROI), and coding services for hospitals nationwide — disclosed a
breach affecting multiple client health systems. Affected organizations included Baptist Memorial Health Care
, Butler Health Systems, Children’s Healthcare of Atlanta, Hoag Health System, and 28+ other hospital systems
and health plans. Ciox processes medical records for approximately 2,000 US hospitals. Exposed data included p
atient names, dates of birth, dates of service, provider names, and medical record numbers. HHS OCR received m
ultiple breach notifications from affected health systems. The Ciox breach illustrated the extreme supply chai
n risk of HIM services vendors that hold PHI from hundreds of hospital clients simultaneously.
Technical Details
- Initial Attack Vector
- Ciox Health — a major health information management (HIM) services provider — suffered a phishing-related breach that exposed patient data across 28+ hospital and health system clients
- Vendor / Product
- Ciox Health (health information management services)
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2022-01-01 Breach occurred
- 2022-01-01 Publicly disclosed