IU Health Data Breach Exposes Vulnerabilities in Third-Party Vendor Cybersecurity

On August 4, 2023, Indiana University Health made public a data breach issue that took place because of third-party vendor’s application of the file transfer system, MOVEit. The vendor in question was TMG Health, Inc.

As per the notice by IU Health, the mentioned incident guided an unauthorized party to be able to access members’ sensitive information. Details such as the names, member identification numbers, and effective dates of plans were amongst the compromised data. This development comes as a warning to legal professionals, corporate, and law firms around the globe to remain alert and further strengthen their data protection measures.

It’s important to note, here, that the rise in cyber threats is not merely a concern for the public and private sectors but has been a global issue for all entities that hold valuable data. This data breach at IU Health, triggered by the actions of TMG Health, Inc., is further proof that cybersecurity needs to remain a top priority for all organizations.

The specific functions of MOVEit – the file transfer program used by TMG Health, and the manner in which the application was exploited in this breach are essential areas for investigation, and could prove valuable in preventing future incidents of a similar nature.

More about this can be read on the original report.