Supply chain ⛓ Supply Chain

American Health Imaging, Banner Medical Group, Belle Point Dental, Duck Creek Family Dental, Partners In Periodontics, and 652 organizations Third-Party Breach (July 2022)

📅 2022-07-01 🏢 Professional Finance Company
Primary Source ↗

Incident Details

Ransomware attack one of year’s biggest health data breaches. A cyberattack on a little-known debt collection firm affects over 650 healthcare facilities across the U.S. A ransomware attack on a little-known debt collection firm that serves hundreds of hospitals and medical facilities across the U.S. could be one of the biggest data breaches of personal and health information this year. The Colorado-based Professional Finance Company, known as PFC, which contracts with “thousands” of organizations to process customer and patient unpaid bills and outstanding balances, disclosed on July 1 that it had been hit by ransomware months earlier in February. Third-party company: Professional Finance Company.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Professional Finance Company
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2022-07-01 Breach occurred
  2. 2022-07-13 Publicly disclosed