Welltok
bd_b765e398c9850ca1 · schema v1 · pii pii-v1
Full breach record for Welltok →Welltok, Inc. disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names, dates of birth, phone numbers, treatment/diagnosis information, prescription information, provider names, medical record numbers, and health insurance information. The company was alerted to the compromise on July 26, 2023, and confirmed the breach on August 11, 2023. Welltok engaged third-party cybersecurity specialists, reconstructed systems, and is offering 12 months of credit monitoring via Experian to affected individuals. The incident impacts residents of California and Rhode Island, among others.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_063b1deb8c7a2bffMaine State AGfiled 2023-12-15Verified by operator
- bd_69d99adc86ef4dcfVermont State AGfiled 2023-12-15Verified
- bd_e5a605be617ae396New Hampshire State AGfiled 2023-12-15Verified
- bd_0328ea1fdab9c459Maine State AGfiled 2023-12-22(7d gap)Verified by operator
Show 6 more filings ↓Show fewer ↑up to 22d gap
- bd_5e4b7107bd1176deCalifornia State AGfiled 2023-12-22(7d gap)Verified
- bd_8ca9e17ac4dfbe9bVermont State AGfiled 2023-12-22(7d gap)Verified
- bd_db6e6d3e58b51e90New Hampshire State AGfiled 2023-12-22(7d gap)Verified
- bd_e378dc71f9be8ac0Maine State AGfiled 2023-12-05(10d gap)Verified by operator
- bd_f5d34ac976e2a29fNew Hampshire State AGfiled 2023-12-05(10d gap)Verified
- bd_f45541c4fa22d1ebMaine State AGfiled 2023-11-23(22d gap)Verified by operator
Showing first 10 of 16 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578029
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2023
- Raw hash
- 944d8fd1d116bf34bc38d9ed6df5c48161dca58c207c4e8846fa7e3d6dc78307
Reporting entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Victim entity
- Name
- Welltoknorm: welltok
- Domain
- welltok.com
Incident
- Discovered
- Jul 26, 2023
- Materiality determined
- —
- Notification sent
- Dec 14, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(142 days from discovery to filing)
- Compliance flags
- CA 60-day late · 141d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 26, 2023→ Notified: Dec 14, 2023141d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.