Supply chain ⛓ Supply Chain

Mobile Medical Response Third-Party Breach (July 2024)

📅 2024-07-01 🏢 CBM Services
Primary Source ↗

Incident Details

Email Breach Affects 22,000 Ambulatory Surgery Center of Westchester Patients. The Mount Kisco Surgery Center, doing business as the Ambulatory Surgery Center of Westchester in New York, has recently notified 22,139 patients that An employee email account containing the PHI of 22,000 Ambulatory Surgery Center of Westchester patients has been hacked. Mobile Medical Response is investigating an impermissible disclosure of patient data. Suspicious activity was detected in an employee’s email account on November 3, 2023, and after securing the account, a forensic investigation was launched to determine the nature and scope of the activity. The investigation confirmed that the unauthorized third party had access to the account from October 23, 2023, to November 3, 2023, and that the account contained patient data. Third-party company: CBM Services.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
CBM Services
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-07-01 Breach occurred
  2. 2024-07-05 Publicly disclosed