Security Experts Weigh in on Quest Diagnostics Vendor Breach

Security Experts Weigh in on Quest Diagnostics Vendor Breach

Quest Diagnostics has warned its 12 million customers that their personal, financial and medical data may have been exposed.

Quest Diagnostics, one of the biggest blood testing providers in the country, has warned its 12 million customers that they may have had their personal, financial and medical information breached due to an issue with one of its vendors.

Quest said it was notified that between Aug. 1, 2018 and March 30, 2019, someone had unauthorized access to the systems of AMCA, a billing collections vendor, according to Wendy Bost, a spokesperson for Quest.

Security experts are weighing in on the additional security risks a company takes on when partnering with outside vendors.

“Once again, a breach that results from third party vulnerabilities,” Colin Bastable, CEO of Lucy Security said. “Outsourcing billing to third party vendors is a great way to extract efficiencies by reducing core costs, but it exposes the business and its customers to uncontrollable security risks. The fragmented healthcare industry, like the fragmented home finance and buying industry, is vulnerable because there are so many moving parts, so many areas where bad actors have multiple points of entry to exploit inadequate security.”

According to Pankaj Parekh, chief product and strategy officer at SecurityFirst, it is not enough to protect just your company’s data, you must also understand the risk associated with sharing that data to third parties.

“Enterprises like Quest Diagnostics must carefully assess the security practices of their vendors to make sure that customer data is secured,” Parekh said. “This is a lot more work for already stretched security and IT teams.”

Laurence Pitt, security strategy director at Juniper Networks, stressed that you cannot outside security responsibility.

“Although there’s no evidence in weakness of the security that Quest Diagnostics are using, this was a breach through a vendor in their supply chain and shows that however good your security strategy is, it can only ever be as good as the weakest link in the chain – and that could easily be a third party,” Pitt said. “It’s essential to evaluate security for every link in the supply chain, and data-protection regulations enforce this.”

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities