HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
WellDyneRx
bd_6ad45f5cd3ac8d9f · schema v1 · pii pii-v1
Full breach record for WellDyneRx →WellDyneRX, LLC, a pharmacy benefit management company, disclosed unauthorized access to an email account between October 30 and November 17, 2021. The breach potentially exposed customer names and government identifiers. WellDyne engaged forensic investigators, secured the account, and notified regulators including HHS. Affected individuals were offered credit monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_d08fab3305d72a6eMaine State AGfiled 2022-09-15Verified
- bd_e9c5de6472f04bb9Washington State AGfiled 2022-09-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-557286
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2022
- Raw hash
- ed2f3e6b98965968c9e24d79a57b427183eba7b9a5322da469e6d720f01003f9
Reporting entity
- Name
- WellDyneRxnorm: welldynerx
Victim entity
- Name
- WellDyneRxnorm: welldynerx
Incident
- Discovered
- Dec 2, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified applicable regulators, including the Department of Health and Human Services
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 41 weeks(287 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.