bioMérieux Announces Third-Party Data Breach Involving MOVEit Transfer Software

Console and Associates, P.C.
Contact

On July 6, 2023, bioMérieux filed a notice of data breach with the Attorney General of Maine after discovering that a file transfer software used by a vendor contained a vulnerability allowing hackers to access confidential consumer information that had been provided to bioMérieux. In this notice, bioMérieux explains that the incident resulted in an unauthorized party being able to access consumers’ sensitive information, which includes their names, Social Security numbers, and protected health information. Upon completing its investigation, bioMérieux began sending out data breach notification letters to the 10,244 individuals whose information was affected by the recent data security incident.

If you received a data breach notification from bioMérieux, it is essential you understand what is at risk and what you can do about it. While this incident did not involve bioMérieux’s computer systems, it did involve confidential consumer information contained in bioMérieux’s member database. As a result, you are now at a much greater chance of falling victim to identity theft or other frauds. A data breach lawyer can help you learn more about how to protect yourself from becoming a victim of fraud or identity theft as well as discuss your legal options following the bioMérieux data breach. For more information, please see our recent piece on the topic here.

What Caused the Data Breach Affecting bioMérieux?

The bioMérieux data breach was only recently announced, and more information is expected in the near future. However, bioMérieux’s filing with the Attorney General of Maine provides some important information on what led up to the breach. According to this source, on June 1, 2023, Vitality Group, one of bioMérieux’s vendors, reported that it learned of a critical vulnerability within MOVEit, a file sharing program used by Vitality.

In response, vitality eliminated the risk and launched an investigation into what files could have been compromised. The Vitality investigation revealed that there was unauthorized access to its member database.

After learning that sensitive consumer data was accessible to an unauthorized party, Vitality reviewed the compromised files to determine what information was leaked and which consumers were impacted. While the breached information varies depending on the individual, it may include your name, Social Security number, and protected health information.

Based on Vitality’s investigation, on July 6, 2023, bioMérieux sent out data breach letters to anyone who was affected by the recent data security incident. Note that this incident did not involve bioMérieux’s computer network; all leaked information was contained within bioMérieux’s member database on the MOVEit platform.

More Information About bioMérieux

Founded in 1963, bioMérieux is a multinational biotechnology company based out of Marcy-l'Étoile, France. The company provides diagnostic solutions to improve patient health and ensure consumer safety. bioMérieux’s products are used for diagnosing infectious diseases, cancer screening and monitoring, and cardiovascular emergencies. They are also used for detecting microorganisms in agri-food, pharmaceutical and cosmetic products. bioMérieux employs more than 13,000 people and generates approximately $3.6 billion in annual revenue.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Console and Associates, P.C. | Attorney Advertising

Written by:

Console and Associates, P.C.
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Console and Associates, P.C. on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide