Supply chain β›“ Supply Chain

Bay Area Heart Center Third-Party Breach (February 2024)

πŸ“… 2024-02-01 🏒 Bowden Barlow Law, P.A.
Primary Source β†—

Incident Details

Des Moines Orthopaedic Surgeons Notifies Patients About February 2023 Data Breach. Des Moines Orthopaedic Surgeons (DMOS) in Iowa has recently notified 307,864 current and former patients that some of their protected health information Data breaches have recently been reported by Des Moines Orthopaedic Surgeons, Prestige Care, Michigan Orthopaedic Surgeons, and Bay Area Heart Center. DMOS said it immediately contained the threat and engaged third-party cybersecurity experts to investigate the incident to determine the extent of compromise. According to the notification letters, β€œDMOS devoted considerable time and effort to assessing the extent and scope of the incident and to determine what information may have been accessible to the unauthorized users.” It took 10 months to determine that patient data was present in the documents and records involved, with PHI exposure not confirmed until December 6, 2023. Third-party company: Bowden Barlow Law, P.A..

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Bowden Barlow Law, P.A.
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-02-01 Breach occurred
  2. 2024-02-06 Publicly disclosed