Welltok MOVEit breach exposed data on 8.5 million US patients
- Organization
- Welltok
- Exploit
- Hacking
- Industry
- Healthcare Software
Welltok, a Denver-based provider of patient engagement and health optimization software, disclosed in late 2023 that files on its MOVEit Transfer server had been stolen during the mass exploitation campaign run by the Clop extortion group. Progress Software alerted customers to the zero-day flaw, tracked as CVE-2023-34362, on May 31, 2023, and Welltok said it applied the patch. Accounts of the intrusion date differ: BleepingComputer reported that the server was breached on July 26, 2023, while the HIPAA Journal and Security Affairs placed initial access on May 30, 2023, with Welltok learning of it on July 26.
Welltok reported the incident to the U.S. Department of Health and Human Services as affecting 8,493,379 people, one of the largest single filings tied to the MOVEit campaign. The company later revised that total upward to 14,762,475.
The exposed records included full names, physical addresses, email addresses, telephone numbers and dates of birth. For a subset of individuals the files also held Social Security numbers, Medicare or Medicaid identification numbers and health insurance details.
Because Welltok operated as a vendor, notifications went out on behalf of its clients. Affected organizations included Blue Cross and Blue Shield plans in Minnesota, Alabama, Kansas and North Carolina, along with Corewell Health, Sutter Health, Stanford Health Care entities, Mass General Brigham Health Plan, Priority Health and The Guthrie Clinic. Welltok began mailing notification letters on November 17, 2023, and said it had no evidence the data had been misused.
Updates
-
The Welltok total on the HHS Office for Civil Rights breach portal was revised to 14,762,475 individuals, up from the 8,493,379 originally reported in November 2023.