Supply chain ⛓ Supply Chain

IACT Health Third-Party Breach (June 2024)

📅 2024-06-01 🏢 Advarra
Primary Source ↗

Incident Details

Patient Data Exposed in Cyberattacks on PruittHealth & Easterseals Central Illinois. PruittHealth has notified patients about a November 2023 ransomware attack and has confirmed that patient data was stolen. Easterseals Central Illinois is PruittHealth has notified patients about a November 2023 ransomware attack and has confirmed that patient data was stolen. Easterseals Central Illinois is investigating a cyberattack that exposed patient data, and IACT Health has been affected by a cyberattack on Advarra. PruittHealth, a health system with 180 care centers facilities in Florida, Georgia, North Carolina, and South Carolina, has confirmed that patient data was stolen in a November 2023 cyberattack. While the “illegal foreign actors” behind the attack were not named in the breach notice, the NoEscape ransomware group claimed responsibility for the attack and said 1.5TB of data was stolen. Third-party company: Advarra.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Advarra
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-06-01 Breach occurred
  2. 2024-06-14 Publicly disclosed