DisclosureLens
Social EngineeringHealthcareFinancial ServicesHealthcarePhishingCustomer Data InvolvedData ExfiltratedIdentity (basic)Government IDFinancial accountPHIHealth (basic)MediumContained

WellCare Health Plans, Inc.

bd_3ec1f1d0918711a7 · schema v1 · pii pii-v2

Severity

Medium

Discovered

Nov 1, 2024

Filed

Sep 10, 2025

To disclose

Affected

1state residents only

Confidence

66%
Full breach record for WellCare Health Plans, Inc.7 incidents on file

MedicareCompareUSA (MCUSA) reported a phishing incident affecting WellCare/Centene policyholders. Unauthorized access occurred between Nov 5-21, 2024, exposing names, DOB, Medicare numbers, and financial account data. One Nebraska resident was notified on Sep 10, 2025. MCUSA provided credit monitoring via Transunion/Cyberscout and notified HHS and credit bureaus.

Incident timeline

Nov 5, 2024

Begins

Sep 10, 2025

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.