C
月内に
米国の医療ネットワーク The Oncology Institute が、サードパーティ製ソフトウェアプロバイダー経由のサイバー攻撃により患者情報が流出したこと…
📌 一言でいうと
米国の医療ネットワーク The Oncology Institute が、サードパーティ製ソフトウェアプロバイダー経由のサイバー攻撃により患者情報が流出したことを明らかにしました。攻撃は2025年に発生し、2025年11月に公表されました。影響を受けたベンダーとして、Cognizant傘下のTriZettoが関与している可能性が指摘されています。
ℹ️ これは他社で発生した事案の情報です。貴社が当該サービスを利用していない場合は、参考情報としてご確認ください。同様の攻撃手法に対する備えのきっかけとしてもご活用いただけます。
🔍該当判定
- 米国の医療機関向けサービス「The Oncology Institute」を利用している
- 医療系ソフトウェアベンダーの「TriZetto」を導入している
- ITアウトソーシング企業「Cognizant」にシステム運用を委託している
- 米国ベースの癌治療ネットワーク(Oncology clinics)とデータ連携を行っている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
サードパーティベンダーのセキュリティ監査の強化、およびサプライチェーンリスク管理の徹底を推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】サードパーティベンダー経由のデータ漏洩事例について
お疲れさまです。外部ベンダーを起点としたデータ漏洩事例に関する情報共有です。
■ 概要
米国の医療機関 The Oncology Institute において、サードパーティ製ソフトウェアプロバイダー(TriZettoの可能性あり)への攻撃を起点とした患者情報の漏洩が発生しました。サプライチェーン攻撃による影響が確認された事例です。
■ 影響範囲
- The Oncology Institute および利用していたサードパーティ製ソフトウェア
■ 対応手順
1. 利用中の外部サービス・ソフトウェアベンダーの侵害状況を確認する
2. ベンダー側でのデータ管理体制およびセキュリティ対策の再評価を行う
3. 侵害発生時の通知フローが確立されているか確認する
■ 参考情報
- secaffairs 報道記事
対応優先度: 低
対応期限: なし
お疲れさまです。外部ベンダーを起点としたデータ漏洩事例に関する情報共有です。
■ 概要
米国の医療機関 The Oncology Institute において、サードパーティ製ソフトウェアプロバイダー(TriZettoの可能性あり)への攻撃を起点とした患者情報の漏洩が発生しました。サプライチェーン攻撃による影響が確認された事例です。
■ 影響範囲
- The Oncology Institute および利用していたサードパーティ製ソフトウェア
■ 対応手順
1. 利用中の外部サービス・ソフトウェアベンダーの侵害状況を確認する
2. ベンダー側でのデータ管理体制およびセキュリティ対策の再評価を行う
3. 侵害発生時の通知フローが確立されているか確認する
■ 参考情報
- secaffairs 報道記事
対応優先度: 低
対応期限: なし
Subject: [Info] Data Breach via Third-Party Vendor at The Oncology Institute
Dear Team,
We are sharing information regarding a recent data breach incident involving a third-party vendor.
■ Overview
The Oncology Institute reported a breach of patient information stemming from a cyberattack on a third-party software provider (potentially TriZetto, owned by Cognizant). This highlights the ongoing risk of supply chain attacks in the healthcare sector.
■ Scope
- The Oncology Institute and its associated third-party software provider.
■ Recommended Actions
1. Review the security posture of current third-party software providers.
2. Evaluate data handling and security controls implemented by external vendors.
3. Ensure that incident notification protocols with vendors are up to date.
■ Reference
- secaffairs report
Priority: Low
Deadline: N/A
Dear Team,
We are sharing information regarding a recent data breach incident involving a third-party vendor.
■ Overview
The Oncology Institute reported a breach of patient information stemming from a cyberattack on a third-party software provider (potentially TriZetto, owned by Cognizant). This highlights the ongoing risk of supply chain attacks in the healthcare sector.
■ Scope
- The Oncology Institute and its associated third-party software provider.
■ Recommended Actions
1. Review the security posture of current third-party software providers.
2. Evaluate data handling and security controls implemented by external vendors.
3. Ensure that incident notification protocols with vendors are up to date.
■ Reference
- secaffairs report
Priority: Low
Deadline: N/A