Supply chain ⛓ Supply Chain

Aptihealth Third-Party Breach (June 2024)

📅 2024-06-01 🏢 Sisense
Primary Source ↗

Incident Details

Almost 20,000 Aptihealth Patients Affected by Business Associate Data Breach. Data breaches have been announced by the behavioral health engagement company Aptihealth and the civil engineering and architecture firm Wilson & Data breaches have been announced by the behavioral health engagement company Aptihealth and the civil engineering and architecture firm Wilson & Company. The Saratoga Springs, NY-based behavioral health engagement company, Aptihealth, has confirmed that the HIPAA protected health information of almost 20,000 patients has been exposed or stolen. The breach occurred at Sisense, a business associate of Aptihealth that provides data analytics services. In order to provide those services, Sisense is given access to Aptihealth data, which includes patients’ protected health information. Third-party company: Sisense.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Sisense
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-06-01 Breach occurred
  2. 2024-06-19 Publicly disclosed