Supply chain ⛓ Supply Chain

Continuum Health Alliance Third-Party Breach (May 2024)

📅 2024-05-01 🏢 Consensus Medical Group
Primary Source ↗

Incident Details

Continuum Health Alliance Data Breach Affects 377,000 Consensus Medical Group Patients. Marlton, NJ-based Continuum Health Alliance has recently confirmed that it has experienced a security incident that exposed the data of 377,119 patients Continuum Health Alliance has reported a breach of the data of more than 377,000 patients of Consensus Medical Group. Guardant Health said an employee error resulted in patient data being inadvertently exposed on an online platform. On February 16, 2024, Continuum announced on its website that it was investigating the incident. The file review was completed on March 8, 2024, when it was confirmed that the exposed data included patients’ names and Social Security numbers. Continuum then worked to verify the information and obtain up-to-date address information, and HIPAA notification letters were mailed on April 29, 2024. Third-party company: Consensus Medical Group.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Consensus Medical Group
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-05-01 Breach occurred
  2. 2024-05-06 Publicly disclosed