Welltok, a third-party vendor working with health plan providers, suffered a data breach impacting 8,493,379 individuals.
What happened
On May 30, 2023, Welltok, Inc. experienced a significant data breach when an unauthorized actor exploited vulnerabilities and accessed their MOVEit Transfer server. This led to the exfiltration of sensitive data. The breach initially went unnoticed until July 26, 2023, when Welltok was alerted to potential vulnerabilities in their server software. Despite having previously installed all necessary patches provided by Progress Software, the developer of the MOVEit Transfer tool, Welltok's initial assessments did not reveal any compromise. On August 11, 2023, Welltok confirmed that the unauthorized access and data extraction had occurred. Following this, they conducted a detailed reconstruction and review of the server data, and by August 26, 2023, Welltok identified that the data related to certain individuals had been compromised during this security incident.
The backstory
The Welltok data breach, part of a series of cyberattacks attributed to the Clop ransomware group, significantly impacts the healthcare sector. This breach mirrors similar incidents at Oregon Health Plan and UMass Chan Medical School, where millions of patients' sensitive data were compromised. These breaches, resulting from vulnerabilities in the MOVEit Transfer system identified by the Cybersecurity & Infrastructure Security Agency (CISA) in June, highlight a worrying trend of targeted attacks on healthcare data. The involvement of the Clop group, known for exploiting software vulnerabilities and demanding ransoms, underscores the evolving challenge of cybersecurity in protecting highly sensitive health information.
Going deeper
October 24, 2023, Welltok, Inc. announced a data breach affecting certain individuals' personal information privacy. In addition to this direct communication with affected parties, Welltok also fulfilled its regulatory obligations by reporting the incident to the appropriate authorities, including the Attorney General of Maine. The organizations affected by this breach include:
- Altru
- Asuris Northwest Health
- BridgeSpan Health
- Blue Cross and Blue Shield of Minnesota and Blue Plus
- Blue Cross and Blue Shield of Alabama
- Blue Cross and Blue Shield of Kansas
- Blue Cross and Blue Shield of North Carolina
- Centerwell Pharmacy
- CHI Health – NE
- CHI Memorial – TN
- CHI Memorial – GA
- CHI Mercy Health
- CHI St. Joseph Health
- CHI St. Luke’s Health Brazosport
- CHI St. Luke’s Health Memorial
- CHI St. Vincent
- Community Health Network
- Corewell Health
- Ella EM Brown Charitable Circle dba Oaklawn Hospital
- Faith Regional Health Services
- Holzer Health System
- Horizon Blue Cross Blue Shield of New Jersey
- Hospital & Medical Foundation of Paris, Inc. dba Horizon Health
- Humana Inc.
- Marshfield Clinic Health System
- Mass General Brigham Health Plan
- Mercy Med Ctr Des Moines-IA
- MercyOne Newton Med Ctr-IA (Skiff)
- Mercy Med Ctr W Lakes Des Moines-IA
- Mercy Med Ctr Centerville-IA
- MercyOne IA Heart Des Moines-IA
- Priority Health
- Regence BlueCross BlueShield of Oregon
- Regence BlueShield
- Regence BlueCross BlueShield of Utah
- Regence Blue Shield of Idaho
- St. Alexius Health
- St Anthony Hospital
- St. Bernards Healthcare
- St Joseph Health
- St. Luke’s Health
- Sutter Health
- ThedaCare, Inc.
- Trane Technologies Company LLC and/or group health plans sponsored by Trane Technologies Company LLC or Trane U.S. Inc.
- Trinity Health
- The group health plans of Stanford Health Care, of Stanford Health Care, Lucile Packard Children’s Hospital Stanford, Stanford Health Care Tri-Valley, Stanford Medicine Partners, and Packard Children’s Health Alliance
- The Guthrie Clinic
- Virginia Mason Franciscan Health
What was said
Welltok's statement offered: “ We take this event and the security of personal information in our care very seriously. Upon learning of this event, we moved quickly to investigate and respond to the event and notify potentially affected individuals. As part of our ongoing commitment to the security of information, we are reviewing and enhancing our existing policies and procedures related to data privacy to reduce the likelihood of a similar future event.”
The bottom line
The Welltok breach and similar incidents orchestrated by the Clop ransomware group serve as a stark reminder of the urgent need for strengthened cybersecurity measures, particularly in the healthcare sector. These breaches, exposing millions of patients' sensitive data, emphasize the need for vigilance and proactive security strategies in protecting against increasingly sophisticated cyber threats. Healthcare organizations, as well as software developers like those of MOVEit, must prioritize regular security updates, comprehensive vulnerability assessments, and data protection protocols.
See also: HIPAA Compliant Email: The Definitive Guide
Subscribe to Paubox Weekly
Every Friday we'll bring you the most important news from Paubox. Our aim is to make you smarter, faster.