Supply chain β›“ Supply Chain

Pavilion of Bridgeview Third-Party Breach (December 2024)

πŸ“… 2024-12-01 🏒 PointClickCare
Primary Source β†—

Incident Details

Gastroenterology, Cardiology, and Nursing Care Providers Suffer Cyberattacks. Cyberattacks have recently been announced by Connecticut GI and Gastroenterology Associates of Fairfield, Cardiology Associates of Mobile, and Pavilion of Cyberattacks have recently been announced by Connecticut GI and Gastroenterology Associates of Fairfield, Cardiology Associates of Mobile, and Pavilion of Bridgeview. Connecticut GI and Gastroenterology Associates of Fairfield have recently confirmed that the protected health information of 10,568 patients was stolen in a security breach in June 2024. The clinics learned on June 19, 2024, that an unauthorized individual had accessed servers between June 5 and June 7, 2024, and copied data. Third-party company: PointClickCare.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
PointClickCare
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-12-01 Breach occurred
  2. 2024-12-05 Publicly disclosed