Supply chain
⛓ Supply Chain
Virginia Dept. of Medical Assistance Services Third-Party Breach (October 2023)
Primary Source ↗Incident Details
September 2023 Healthcare Data Breach Report. September was a much better month for healthcare data privacy, with the lowest number of reported healthcare data breaches since February 2023. In. For the second successive month, there was a fall in the number of breached records, which dropped 36.6% month-over-month. Across the 48 reported data breaches, the protected health information of 7,556,174 individuals was exposed or impermissibly disclosed. September’s total was below the 12-month average of 7,906,890 records per month, but this year has seen two particularly bad months for data breaches. More healthcare records were exposed in May and June than were exposed in all of 2020!. Third-party company: Maximus.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Maximus
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2023-10-01 Breach occurred
- 2023-10-20 Publicly disclosed