On August 10, an unauthorized actor exploited a critical vulnerability in the Metabase platform to obtain administrator access to Blueberry’s Metabase environment. The activity was associated with broader exploitation of the Metabase vulnerability. On August 22, Blueberry detected the unauthorized access and initiated its incident-response process. Within approximately one hour of detection, Blueberry terminated the unauthorized access and associated sessions and preserved relevant logs and system evidence. To prevent future occurrences and in light of the Metabase incident, Blueberry Medical has strengthened its authentication, implemented an additional monitoring and escalation process for its vendors’ critical vulnerabilities, and increased the frequency of security reviews for third-party and self-hosted technology infrastructure, such as Metabase. Blueberry also confirmed that Metabase was running a non-vulnerable version by then. Blueberry also reached out to law enforcement and retained a leading forensic and cyber security response firm.
Information that may have been exposed in this incident includes: name, health plan name and policy number, date of birth, and health care information such as medical records, dates of service, medical codes, and charges for services. Although this incident did not involve certain sensitive financial information that would increase the risk of identity theft, we are providing the following information to you out of an abundance of caution. We recommend that you remain vigilant by reviewing account statements and monitoring free credit reports. You should promptly report any suspicious activity or suspected identity theft to the proper law enforcement authorities, including local law enforcement, your state’s attorney general, and/or the Federal Trade Commission (“FTC”).
If you have any questions regarding this matter, please call us at 888-752-8498 Monday through Friday, 9:00 AM to 9:00 PM, Eastern Time or email us at privacy@blueberrymed.com
View source version on businesswire.com: https://www.businesswire.com/news/home/20261009748496/en/
Contacts
If you believe this article contains misleading, harmful, or spam content, please let us know.
Report this article