Supply chain
⛓ Supply Chain
Continuum Health Alliance Third-Party Breach (May 2024)
Primary Source ↗Incident Details
Continuum Health Alliance Data Breach Affects 377,000 Consensus Medical Group Patients. Marlton, NJ-based Continuum Health Alliance has recently confirmed that it has experienced a security incident that exposed the data of 377,119 patients Continuum Health Alliance has reported a breach of the data of more than 377,000 patients of Consensus Medical Group. Guardant Health said an employee error resulted in patient data being inadvertently exposed on an online platform. On February 16, 2024, Continuum announced on its website that it was investigating the incident. The file review was completed on March 8, 2024, when it was confirmed that the exposed data included patients’ names and Social Security numbers. Continuum then worked to verify the information and obtain up-to-date address information, and HIPAA notification letters were mailed on April 29, 2024. Third-party company: Consensus Medical Group.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Consensus Medical Group
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2024-05-01 Breach occurred
- 2024-05-06 Publicly disclosed