The breach originated from an unpatched vulnerability in a billing software provider used by several major hospital networks. Exposed data includes Social Security numbers, medical histories, and health insurance information.
Affected individuals are being offered credit monitoring, but the long-term risk of medical identity theft is profound. Medical providers are now revisiting their vendor risk management strategies.
