Sutter Health says MOVEit breach at vendor Welltok exposed 845,000 patients

Organization
Sutter Health
Exploit
Supply Chain Attack
Industry
Healthcare

Sutter Health, a Northern California nonprofit health system, told patients on November 3, 2023 that their information had been taken from a vendor rather than from its own systems. The vendor, Welltok Inc., a Virgin Pulse company, operated the online contact-management platform Sutter used for patient communications.

An unauthorized actor exploited vulnerabilities in the MOVEit Transfer file transfer software on Virgin Pulse's server and exfiltrated data on May 30 and 31, 2023, part of the Clop ransomware operation's mass exploitation of MOVEit that summer. Virgin Pulse notified Sutter Health on September 22 and delivered a final investigation report on October 24.

Sutter Health put the number of affected patients at approximately 845,441. Reporting on the notice described the exposed fields as names, dates of birth, health insurance information, provider names, treatment cost information and diagnosis or treatment details. Sutter Health said Social Security numbers and financial information were not impacted.

Virgin Pulse applied patches, took further mitigation steps and engaged outside cybersecurity specialists. Sutter Health published the notice on its Vitals news site. Virgin Pulse notified impacted patients by mailed letters and set up a dedicated assistance line at 800-628-2141. The health system framed the incident throughout as a vendor breach rather than a compromise of its own network.

Sources