HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedBusiness Associate (HIPAA)IDENTITY_BASICLowContained
California Physicians' Services
bd_a6884d47e386af7d · schema v1 · pii pii-v1
Full breach record for California Physicians' Services →Welltok, Inc., a third-party service provider for Blue Shield of California, disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. Welltok was alerted to the compromise on July 26, 2023. The incident affects Blue Shield members. Welltok is offering credit monitoring services.
California clockDiscovered Jul 26, 2023 → Notified Dec 21, 2023148d ✗ CA 60-day late23 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578830
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 4, 2024
- Raw hash
- 97c498cf78ae6b884fe6c4ae2c475386cb0234ed8e4522555ad9c786dac3ef6c
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- California Physicians' Servicesnorm: california physicians
- Domain
- blueshieldca.com
Incident
- Discovered
- Jul 26, 2023
- Materiality determined
- —
- Notification sent
- Dec 21, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Welltok, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 23 weeks(162 days from discovery to filing)
- Compliance flags
- CA 60-day late · 148d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 26, 2023→ Notified: Dec 21, 2023148d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.