HackingBusiness Associate (HIPAA)Customer Data InvolvedDownstream VictimsLow
the group health plans of Stanford Health Care, of Stanford Health Care, Lucile Packard Children's Hospital Stanford, Stanford Health Care Tri-Valley, Stanford Medicine Partners, and Packard Children's Health Alliance
bd_2f0ba9196cb9de3b · schema v1 · pii pii-v1
Full breach record for the group health plans of Stanford Health Care, of Stanford Health Care, Lucile Packard Children's Hospital Stanford, Stanford Health Care Tri-Valley, Stanford Medicine Partners, and Packard Children's Health Alliance →Welltok, Inc., a business associate for Stanford Health Care and its affiliated health plans, reported a data breach affecting 8 Maine residents. The incident was an external system breach that occurred on May 30, 2023. Affected individuals were notified on October 17, 2023, and offered credit monitoring and identity restoration services through Experian.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed8 affectedView incident
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/78e177b2-14ba-4d97-a8cf-eeaa3f1ba0b8.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 18, 2023
- Raw hash
- 58bfacccb404dfb9d591a043a8b05d41fff3af028a4d92e8e4e30fb3bfdfc8c4
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- the group health plans of Stanford Health Care, of Stanford Health Care, Lucile Packard Children's Hospital Stanford, Stanford Health Care Tri-Valley, Stanford Medicine Partners, and Packard Children's Health Alliancenorm: the group health plans of stanford health care of stanford health care lucile packard children s hospital stanford stanford health care tri valley stanford medicine partners and packard children s health alliance
- Industry
- Healthcare
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Oct 17, 2023
- Affected individuals
- 8
- Data types
- —
- Attack vector
- Unauthorized Access
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.