Supply chain
⛓ Supply Chain
Entira Family Clinics Third-Party Breach (January 2022)
Primary Source ↗Incident Details
Family Medicine Practice Notifies Patients of Data Breach 1 Year Later | TechTarget. Netgain discovered the data breach in late 2020, but a Minnesota family medicine practice notified its patients in January 2022. Entira Family Clinics, a family medicine practice based in Minnesota, sent data breach notification letters to impacted individuals via the Maine Attorney General’s Office on January 13, 2022. The Maine Attorney General’s Office said that the breach impacted nearly 200,000 individuals associated with the family medicine practice. In the letter, Entira wrote that it had “recently discovered” a data breach that occurred within Netgain Technology, a cloud hosting provider. Third-party company: Netgain.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Netgain
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2022-01-01 Breach occurred
- 2022-01-18 Publicly disclosed