Supply chain
β Supply Chain
Bay Area Heart Center Third-Party Breach (February 2024)
Primary Source βIncident Details
Des Moines Orthopaedic Surgeons Notifies Patients About February 2023 Data Breach. Des Moines Orthopaedic Surgeons (DMOS) in Iowa has recently notified 307,864 current and former patients that some of their protected health information Data breaches have recently been reported by Des Moines Orthopaedic Surgeons, Prestige Care, Michigan Orthopaedic Surgeons, and Bay Area Heart Center. DMOS said it immediately contained the threat and engaged third-party cybersecurity experts to investigate the incident to determine the extent of compromise. According to the notification letters, βDMOS devoted considerable time and effort to assessing the extent and scope of the incident and to determine what information may have been accessible to the unauthorized users.β It took 10 months to determine that patient data was present in the documents and records involved, with PHI exposure not confirmed until December 6, 2023. Third-party company: Bowden Barlow Law, P.A..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Bowden Barlow Law, P.A.
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-02-01 Breach occurred
- 2024-02-06 Publicly disclosed