Supply chain ⛓ Supply Chain

Geisinger Third-Party Breach (June 2024)

📅 2024-06-01 🏢 Nuance Communications
Primary Source ↗

Incident Details

Former IT employee accessed data of over 1 million US patients. Geisinger, a prominent healthcare system in Pennsylvania, has announced a data breach involving a former employee of Nuance, an IT services provider contracted by the organization. Geisinger is a non-profit organization that operates 134 care sites, ten hospitals, and the Geisinger Health Plan, serving a total of 1.2 million people. It employs 26,000 staff, including 1,600 doctors, and is considered one of Pennsylvania’s most important organizations. An announcement published earlier this week explains that in November 2023, Geisinger detected unauthorized access to its patients’ database by a former Nuance employee. Third-party company: Nuance Communications.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Nuance Communications
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-06-01 Breach occurred
  2. 2024-06-27 Publicly disclosed