In theory, Web 3.0 will give rise to a smarter internet, where the unique ownership of digital identity can be achieved throughself-sovereign identity, and distributed services will thrive in a decentralized network.

These initiatives are expected to improve security, but no one has fully achieved them yet. Data flows too smoothly between entities, making it nearly impossible to store it securely during every transmission and operation. There are indeed companies that excel at protecting data, but the security of these companies is only as strong as the weakest link in their supply chain.

The weak link for Quest Diagnostics and LabCorp was their shared billing agency, the American Medical Collection Agency (AMCA).

"Frankly, I think it's a hopeless situation," Gartner distinguished vice president analyst Avivah Litan told CIO Dive.

"Between consumers and the companies that directly serve them, there are a large number of backend data aggregators, brokers, service providers, etc.," Litan said. "Only a complete overhaul of how consumer data flows and who controls it can make a substantial difference in data protection."

Web 3.0, self-sovereign identity, and decentralized networks are at least decades away, meaning data breaches will continue to occur, followed by companies offering free credit monitoring to make amends. (AMCA is offering 24 months of credit monitoring services to affected individuals.)

The anatomy of the breach

The healthcare industry led all sectors in 2018cybersecurity incidents, accounting for one-third of all potentially breached records. On average, healthcare organizations take 36 days to detect an initial intrusion and an additional 10 days to contain the situation.

Unauthorized access at AMCA lasted about eight months, from August 2018 to March 30, 2019. The intrusion affected AMCA's clients, including nearly12 million patientsof Quest Diagnostics, and its competitor LabCorp'snearly 8 million patients

According to Quest's latest SEC filing, AMCA informed the clinical testing company of "potential unauthorized activity" on its web payment page.

The intrusion led to unauthorized access to Quest's financial information, including patient credit card numbers, bank account information, and medical and other personally identifiable information (PII) such as Social Security numbers.

Data breached at LabCorp included names, dates of birth, addresses, phone numbers, dates of service, service providers, and balance information,as detailed in its SEC filing. Unlike Quest, LabCorp "did not provide AMCA with any test orders, laboratory results, or diagnostic information," so medical records were not affected. AMCA also did not store LabCorp patients' Social Security numbers and other PII, which put Quest under greater pressure.

The AMCA incident is far smaller in scale than the 2015 breach at health insurer Anthem, whichexposed data of 80 million members and employees. That incident is believed to have originated from the company's failure to patch a known vulnerability, leading to a state-sponsored cyberattack. Anthem was also criticized for slow notification and for not encrypting PII and health data.

AMCA is currently conducting a post-incident investigation to determine what went wrong and who the intruders were.

"After receiving notification from a security compliance firm working with credit card companies about a possible security intrusion, we conducted an internal review and then took the web payment page offline," AMCA said in an email statement to CIO Dive.

The collection agency "migrated the web payment portal service to a third-party vendor" and sought help from other consultants and law enforcement.

But AMCA has refused to call the cybersecurity incident a "breach," instead calling it a "potential breach."

The word "breach" carries an unforgivable connotation, making a company seem irresponsible. Equifax's breach, two years on, still affects its reputation. Recently, the credit bureau was hit by Moody's firstoutlook downgrade

over the breach. But unlike Equifax, AMCA's "potential breach" is having ripple effects on its healthcare clients.

"Frankly, it's a shared responsibility," Litan said. Ensuring security compliance outside one's own organization may seem impossible, but it is necessary. "Unfortunately, without continuous verification, no one can trust others' security practices."

Even if ecosystem partners are largely trustworthy, their security must be "consciously assessed," Litan said.

The weight of medical data

Medical record breaches further erode consumer trust in large enterprises to protect data. When medical data joins the ranks of stolen data, the stakes escalate significantly for malicious actors and their potential victims.

Malicious actors could "impersonate healthcare providers and send emails with lab results that, when opened, actually contain malware, as a social engineering attack," Litan said.

Because medical records often contain information accessible only to patients and doctors, attackers may demand ransom or threaten to expose data, Matt Kunkel, CEO of LogicGate, told CIO Dive. Secondary attacks—disguised as ransomware, phishing schemes, or identity theft—are more likely because malicious actors can buildmore detailed personal profiles

Medical records provide attackers with a more intimate profile than names and Social Security numbers alone. Health records could be "used by state actors to kill targeted victims," Litan said. This could be accomplished by sending dangerous substances disguised as seemingly legitimate pharmaceutical packages to patients.

The severity of the situation has not been ignored by Congress, which has heard testimony from multipleexecutives of breached companies. Three U.S. senators—Democrats Bob Menendez and Cory Booker of New Jersey, and Democrat Mark Warner of Virginia—sent a letter of inquiry to Quest Diagnostics' CEO.

"While I am relieved to learn that there is currently no evidence that Quest Diagnostics' systems were compromised, I am concerned about your company's supply chain management and third-party selection and monitoring processes,"Warner wrote. "I would like to learn more about your company's vendor selection and due diligence processes... given this vendor's vulnerabilities and information security failures."

Menendez and Booker asked Quest how many security tests "assessing both Quest Diagnostics' systems and those of its outsourcing companies" were conducted during the AMCA exposure.

Jeff Roth, Southeast regional director at security consulting firm NCC Group, told CIO Dive that given the state of commercial and government supply chains, companies need to consider the following questions:

  • What is the number and type of outsourced services? Which are performed offshore?
  • How and to what extent do service providers, business partners, and subcontractors comply with security requirements?
  • How deep and how frequent is supply chain threat and risk analysis?
  • Does the company have sufficient resources to implement an effective agile supply chain cybersecurity program?

Key risk factors in the supply chain include: using unqualified hosting services, failing to incorporate company cybersecurity requirements into vendor contracts, and failing to fully integrate the supply chain into the company's continuous threat monitoring, Roth said.

The standards companies hold themselves to should also apply to partners before signing security contracts.

In a security-as-a-service model, companies cannot assume the provider will handle everything; most of the time they only provide a firewall. Follow-up questions—what services are provided, how often patches are deployed, vulnerability analysis, and ultimately the cost of these services—are necessary. The same should apply to other vendors.

Before locking in a vendor, companies should establish strict requirements to ensure the confidentiality of customer data, Asher de Metz, principal security consultant at Sungard Availability Services, said in an email to CIO Dive.

If more AMCA clients report secondary breach impacts, similar senatorial inquiries will arise. Did companies require AMCA to provide evidence of penetration testing? What was its security program data? de Metz asked. "Companies should not blindly trust partners."

Senators want to understand how third-party failures could so severely affect patients. The intrusion occurred within AMCA, but responsibility is shared across its partner ecosystem.

Contractual requirements lock in expectations for partners in the supply chain ecosystem. They also designate a single entity to disclose information to shareholders, customers, the public, and regulators, Roth said. Other parties along the supply chain each have roles in incident recovery.

"The primary reason is to prevent inaccurate or even misleading information from being released, or information that could impede criminal and civil investigations," Roth said.