Supply chain β›“ Supply Chain

Medicare & Medicaid Services (CMS) Third-Party Breach (May 2023)

πŸ“… 2023-05-01 🏒 Palmetto GBA
Primary Source β†—

Incident Details

Mailing Error at CMS Vendor Affects 10,000 Medicare Beneficiaries. The Centers for Medicare & Medicaid Services (CMS) has started notifying certain Medicaid beneficiaries about an impermissible disclosure of some of A mailing error at a CMS vendor has resulted in the impermissible disclosure of the PHI of 10,000 Medicare beneficiaries. UHS of Delaware and Northeast Behavioral Health Care Consortium have confirmed patient data has been exposed in phishing attacks. Third-party company: Palmetto GBA.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Palmetto GBA
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2023-05-01 Breach occurred
  2. 2023-04-27 Publicly disclosed