Supply chain
⛓ Supply Chain
Geisinger Third-Party Breach (June 2024)
Primary Source ↗Incident Details
Former IT employee accessed data of over 1 million US patients. Geisinger, a prominent healthcare system in Pennsylvania, has announced a data breach involving a former employee of Nuance, an IT services provider contracted by the organization. Geisinger is a non-profit organization that operates 134 care sites, ten hospitals, and the Geisinger Health Plan, serving a total of 1.2 million people. It employs 26,000 staff, including 1,600 doctors, and is considered one of Pennsylvania’s most important organizations. An announcement published earlier this week explains that in November 2023, Geisinger detected unauthorized access to its patients’ database by a former Nuance employee. Third-party company: Nuance Communications.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Nuance Communications
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2024-06-01 Breach occurred
- 2024-06-27 Publicly disclosed