Third-party data breach round-up: mscripts, Diligent, Mailchimp

This month, more than 114,000 individuals may have experienced personally identifiable information and protected health information exposures from these incidents, while an email marketing hack is a new source for phishing attacks.

Medication adherence platform mscripts breached

On January 17, mscripts, a cloud-based mobile pharmacy platform that focuses on patient engagement and medication adherence solutions, reported to the U.S. Department of Health and Human Services unauthorized access/disclosure that involved protected health information of 66,372 individuals, according to the Office for Civil Rights cases under investigation list.

The San Francisco-based platform, owned by Dublin, Ohio-based Cardinal Health, uses interactive SMS messaging and branded mobile apps to provide dosage and refill reminders and other prescription management functions. 

It has partnerships across the healthcare space and customers include retailers like Kmart and Wegmans, and providers like Intermountain Healthcare, Banner Health and the Henry Ford Health System.

Mscripts and Cardinal Health have not posted data breach notices to their websites.

The mscripts privacy policy on Henry Ford’s website indicates that PII, as well as PHI, may be collected by mscripts from users and their pharmacies. 

Diligent Corporation announced PII compromised, exposed UCHealth data

According to a UCHealth announcement posted to its website January 17, “Diligent provides hosted services to UCHealth and reported to UCHealth that Diligent’s software was accessed and attachments were downloaded including UCHealth files.”

The Colorado-based healthcare provider noted that electronic medical records and email systems were not part of the breach, but “some of UCHealth’s patient, provider or employee data may have been included in this incident.” 

UCHealth reported to OCR that 48,879 individuals were affected by the hacking incident, according to the agency.

The medical provider said the stolen data may have included:

  • Name.
  • Address.
  • Date of birth.
  • Treatment-related information.
  • Social Security numbers.
  • Other financial information.

Mailchimp’s second social engineering attack, CloudSEK reports leaked API keys

Mailchimp announced on its website that on January 11 it identified an unauthorized actor had compromised administration tools and accessed 133 accounts, exposing customer data, through a second social engineering attack on the company in six months. 

The email marketing service provider temporarily suspended those accounts to protect user data. 

Mailchimp was first breached in April 2022, and threat actors were able to view around 300 user accounts and obtain audience data from 102 of them, as reported by the chief information security officer to the HHS cybersecurity program. 

As a result, HC3 warned healthcare organizations of phishing campaigns leveraged by the email marketing platform. 

While it is not a HIPAA-covered entity with a business associate agreement, a number of medical practice management applications integrate with Mailchimp, and a number of mail marketing service providers for doctors and providers work with Malchimp, Constant Contact and other email marketing platforms.

In the previous social engineering attack in August, Mailchimp specified that the 214 accounts affected were largely cryptocurrency and finance organizations.

However, DigitalOcean, a large cloud provider across industries, including healthcare, confirmed its clients had been affected by malicious password resets, and the provider migrated email services away from the platform.

Also, CloudSEK’s BeVigil research team released a December report that API keys for Mailchimp, along with Mailgun and Sendgrid, had been leaked, potentially allowing threat actors access to email conversations and potentially sensitive information.

“An API key leak in Mailchimp would allow a threat actor to read conversations, fetch customer information, expose email lists of multiple campaigns containing [PII], authorize third-party applications connected to a MailChimp account, manipulate promo codes and start a fake campaign and send emails on behalf of the company,” according to Business Standard’s coverage of the report.

Andrea Fox is senior editor of Healthcare IT News.
Email: af**@***ss.org

Healthcare IT News is a HIMSS publication.

Read More
Christeen Damron

Latest

Broncos football player arrested for second time in 8 days

Broncos football player arrested for second time in 8 days Denver Broncos linebacker Jonathon Cooper is facing additional legal trouble after authorities arrested him for allegedly violating a court-issued protection order connected to an ongoing domestic violence case. According to police, Cooper was taken into custody after allegedly contacting and visiting his girlfriend despite being

NFL vs. College Football: Highest Earnings by Position in New NIL Era

NFL vs. College Football: Highest Earnings by Position in New NIL Era The gap between professional and college football earnings remains substantial, even as NIL opportunities have transformed the landscape for elite college athletes. According to Football Scoop and NIL Standard, top NFL players still earn significantly more than the highest-paid college players at the

Deion Sanders Received Bonus He Didn’t Earn as Colorado’s $1.2M Blunder Surfaces: Report

When CU brought Deion Sanders in 2023, it was not just for football. It was also a business move. He brought cameras, celebrities, huge television ratings, and a level of attention that Colorado had not seen in decades. Quickly, CU got attention, and it helped explain why the program rewarded Sanders with a $250,000 discretionary

Moving Yahya Black To Nose Tackle Isn’t A Seismic Change

According to accounts from the Pittsburgh Steelers’ coaching staff and beat writers attending spring practices, Yahya Black is playing nose tackle. New defensive line coach Domata Peko suggested Black could become one of football’s best nose tackles. It’s a different framing than a year ago, when Pittsburgh’s old regime viewed Black as a defensive end

Newsletter

Don't miss

Broncos football player arrested for second time in 8 days

Broncos football player arrested for second time in 8 days Denver Broncos linebacker Jonathon Cooper is facing additional legal trouble after authorities arrested him for allegedly violating a court-issued protection order connected to an ongoing domestic violence case. According to police, Cooper was taken into custody after allegedly contacting and visiting his girlfriend despite being

NFL vs. College Football: Highest Earnings by Position in New NIL Era

NFL vs. College Football: Highest Earnings by Position in New NIL Era The gap between professional and college football earnings remains substantial, even as NIL opportunities have transformed the landscape for elite college athletes. According to Football Scoop and NIL Standard, top NFL players still earn significantly more than the highest-paid college players at the

Deion Sanders Received Bonus He Didn’t Earn as Colorado’s $1.2M Blunder Surfaces: Report

When CU brought Deion Sanders in 2023, it was not just for football. It was also a business move. He brought cameras, celebrities, huge television ratings, and a level of attention that Colorado had not seen in decades. Quickly, CU got attention, and it helped explain why the program rewarded Sanders with a $250,000 discretionary

Moving Yahya Black To Nose Tackle Isn’t A Seismic Change

According to accounts from the Pittsburgh Steelers’ coaching staff and beat writers attending spring practices, Yahya Black is playing nose tackle. New defensive line coach Domata Peko suggested Black could become one of football’s best nose tackles. It’s a different framing than a year ago, when Pittsburgh’s old regime viewed Black as a defensive end

Navy Coach Shares Why ‘Gritty Guy’ Eli Heidenreich Can Carve Out Special Teams Role With Steelers

Making a 53-man roster in the NFL is a tough task, especially for a seventh-round pick. It’s a long, challenging road, and the odds are stacked against you. So, the more you can do for a football team, the better. Pittsburgh Steelers rookie running back and wide receiver Eli Heidenreich has the advantage of being

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID

Business groups are fighting Labor’s CGT changes. Here is where SMEs stand

Labor’s most contested tax reform in a generation cleared its first formal hurdle on Thursday and immediately ran into organised resistance. Treasurer Jim Chalmers introduced the government’s tax reform legislation to the House of Representatives on 28 May, bundling together four budget measures: the capital gains tax overhaul, new limits on negative gearing, a $250

Meet the most influential business owners from Southwest Nigeria

This article spotlights the most influential business owners from Southwest Nigeria, adjudged by their dominance in their respective sectors of the economy where they operate. The post Meet the most influential business owners from Southwest Nigeria appeared first on Nairametrics...