Supply chain ⛓ Supply Chain

St. Luke's Third-Party Breach (May 2022)

📅 2022-05-01 🏢 Kaye-Smith
Primary Source ↗

Incident Details

St. Luke’s says customers hit with data breach that may have exposed personal, financial, medical information. St. Luke’s Health System issued a news release Wednesday saying an unknown number of patients were impacted by a data breach. The hospital system said a breach at vendor Kaye-Smith may have exposed a wide array of information, including patient name, insured name, address, phone number, ID number, date of birth, last five digits of […]. St. Luke’s said the breach happened in late May, and impacted customers billed in that same month. The vendor discovered the breach in June and informed St. Luke’s on July 6th. Third-party company: Kaye-Smith.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Kaye-Smith
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2022-05-01 Breach occurred
  2. 2022-07-28 Publicly disclosed