Supply chain ⛓ Supply Chain

Virginia Dept. of Medical Assistance Services Third-Party Breach (October 2023)

📅 2023-10-01 🏢 Maximus
Primary Source ↗

Incident Details

September 2023 Healthcare Data Breach Report. September was a much better month for healthcare data privacy, with the lowest number of reported healthcare data breaches since February 2023. In. For the second successive month, there was a fall in the number of breached records, which dropped 36.6% month-over-month. Across the 48 reported data breaches, the protected health information of 7,556,174 individuals was exposed or impermissibly disclosed. September’s total was below the 12-month average of 7,906,890 records per month, but this year has seen two particularly bad months for data breaches. More healthcare records were exposed in May and June than were exposed in all of 2020!. Third-party company: Maximus.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Maximus
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2023-10-01 Breach occurred
  2. 2023-10-20 Publicly disclosed