HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICPHILowContained
SUTTER HEALTH
bd_8f504197ab096f70 · schema v1 · pii pii-v1
Full breach record for SUTTER HEALTH →Sutter Health notified patients of a data breach involving its third-party vendor, Welltok, Inc. An unknown actor exploited software vulnerabilities in Welltok's MOVEit Transfer server on May 30-31, 2023, exfiltrating data including names and other personal information. Welltok was alerted on July 26, 2023, and confirmed the compromise on August 11, 2023. Affected individuals are offered credit monitoring and identity restoration services.
California clockDiscovered Jul 26, 2023 → Notified Oct 31, 202397d ✗ CA 60-day late14 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_af3fc728ff443e64HHS OCRfiled 2023-11-03Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576106
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 3, 2023
- Raw hash
- 00f55c3bc12ec0c2bbebce02d36065cb8bf4051625513b6d463bb6a60233d208
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- SUTTER HEALTHnorm: sutter health
- Domain
- sutterhealth.org
Incident
- Discovered
- Jul 26, 2023
- Materiality determined
- —
- Notification sent
- Oct 31, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Welltok, Inc.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(100 days from discovery to filing)
- Compliance flags
- CA 60-day late · 97d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 26, 2023→ Notified: Oct 31, 202397d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.