TissuPath patient records leaked after breach at a third-party IT supplier

Organization
TissuPath
Exploit
Supply Chain Attack
Industry
Healthcare

TissuPath, a specialist pathology practice in Melbourne, disclosed in early September 2023 that patient information had been taken from a storage drive reached through compromised accounts at one of its service providers.

The practice said the attackers made contact on August 24, 2023 and threatened to publish patient information within 48 hours unless they were paid. Cyber Daily reported that a vulnerability in the supplier's remote access toolkit allowed the intruders onto the drive and let them obtain administrator credentials. TissuPath said its main database and reporting system, which holds patient diagnoses, was not compromised, and that billing information was not stored on any affected system.

The material involved consisted of scanned pathology request forms covering referrals made between 2011 and 2020, many of them for patients being checked for cancer. Fields included patient names, dates of birth, gender, contact details, Medicare numbers, private health insurance details and referring practitioner information. Records were retained over that period under national pathology accreditation rules.

Threat intelligence researchers attributed the attack to the ALPHV group, also known as BlackCat, although TissuPath's own incident statement did not name it. ALPHV published the files on its leak site, describing the set as 446 gigabytes across 735,414 documents. TissuPath said it had halted the breach and notified referring medical practitioners and government agencies, and ID Support NSW issued guidance for people who believed they might be affected.

Sources