Supply chain ⛓ Supply Chain

Sutter North Surgery Center Patients Third-Party Breach (September 2023)

📅 2023-09-01 🏢 SightPath Medical
Primary Source ↗

Incident Details

PHI of Almost 75,000 Individuals Exposed in Email Incident at AmeriBen. IEC Group, Inc., doing business as AmeriBen, a medical benefits administration services provider, has recently reported an email-related HIPAA data breach AmeriBen says the PHI of almost 75,000 individuals has been exposed in an email incident. Data breaches have also been reported by Sanford Health, SightPath Medical, and Delta Dental of California. AmeriBen said it has no reason to believe that any of the exposed information will be misused but has advised the affected individuals to monitor their Explanation of Benefits statements as a precaution. The email account contained protected health information such as employees’ first and last names, claimants first and last names, case numbers, employer CERT codes, provider name, provider city, claim number, date(s) of service, internal INEL codes, and amounts billed and paid. Third-party company: SightPath Medical.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
SightPath Medical
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2023-09-01 Breach occurred
  2. 2023-09-19 Publicly disclosed