Supply chain
β Supply Chain
Medicare & Medicaid Services (CMS) Third-Party Breach (May 2023)
Primary Source βIncident Details
Mailing Error at CMS Vendor Affects 10,000 Medicare Beneficiaries. The Centers for Medicare & Medicaid Services (CMS) has started notifying certain Medicaid beneficiaries about an impermissible disclosure of some of A mailing error at a CMS vendor has resulted in the impermissible disclosure of the PHI of 10,000 Medicare beneficiaries. UHS of Delaware and Northeast Behavioral Health Care Consortium have confirmed patient data has been exposed in phishing attacks. Third-party company: Palmetto GBA.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Palmetto GBA
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-05-01 Breach occurred
- 2023-04-27 Publicly disclosed