HomeSecurityWelltok: Data breach affects 8.5 million patients

Welltok: Data breach affects 8.5 million patients

Healthcare SaaS provider Welltokis warning of a data breach that exposed the personal information of nearly 8.5 million patients in the United States. The breach was caused by a hack of the MOVEit the company was using.

Welltok Data Breach

Welltok partners with healthcare providers across the U.S. to offer online wellness programs. The company maintains databases of personal data , generating predictive insights and supporting healthcare needs such as medication adherence and pandemic response.

See also: PJ&A: Data breach affects approximately 9 million patients

Earlier this year, the Clop ransomware gang exploited a zero-day vulnerability in MOVEit file transfer software and managed to compromise thousands of organizations. Welltok said in late October that its MOVEit Transfer server had been compromised on July 26, 2023. And, according to the company, this happened despite the prompt implementation of security updates released by the vendor.

The Welltok data breach affects patient addresses email, physical addresses, and phone numbers. In some cases, Social Security Numbers (SSNs), Medicare/Medicaid ID numbers, and certain Health Insurance information have also been exposed.

See also: AutoZone: Warns of data breach via “MOVEit attack”

This breach affected institutions in several states, including Minnesota, Alabama, Kansas, North Carolina, Michigan, Nebraska, Illinois, and Massachusetts. The following healthcare providers are said to have been affected:

  • Blue Cross and Blue Shield of Minnesota and Blue Plus
  • Blue Cross and Blue Shield of Alabama
  • Blue Cross and Blue Shield of Kansas
  • Blue Cross and Blue Shield of North Carolina
  • Corewell Health
  • Faith Regional Health Services
  • Hospital & Medical Foundation
  • Brigham Health Plan
  • Priority Health
  • St. Bernards Healthcare
  • Sutter Health
  • Trane Technologies Company LLC and/or group health plans from Trane Technologies Company LLC or Trane US Inc.
  • Group health plans of Stanford Health Care, Stanford Health Care, Lucile Packard Children's Hospital Stanford, Stanford Health Care Tri-Valley, Stanford Medicine Partners and Packard Children's Health Alliance
  • The Guthrie Clinic

Welltok reported to the U.S. Department of Health and Human Services' breach portal that the data affects 8,493,379 people.

This number places the Welltok breach as the second largest data breach via a MOVEit attack. First is the Maximus attack, where the data breach affected 11 million people.

Welltok: Data breach affects 8.5 million patients

Possible consequences of a patient data breach

The potential consequences of this data breach for affected patients in the United States could be multiple and serious. First, the leaked information includes sensitive personal data that could be used to steal patients' identities.

See also: Kansas Courts: Data Breach After Recent Cyberattack

Additionally, malicious users can use this information to commit other frauds or attempt to gain access to financial or medical systems. This can lead to financial loss, medical history exploitation, etc.

Finally, this breach could lead to legal consequences for Welltok . Affected patients could file lawsuits against the company for privacy violations and inadequate protection of their personal data. This could lead to financial damages and further losses for the company

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS