Elixir Pharmacy
bd_b8f67070c4cc8147 · schema v1 · pii pii-v1
Full breach record for Elixir Pharmacy →Welltok, Inc., a service provider for Elixir Pharmacy, disclosed that an unknown actor exploited software vulnerabilities in a MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. Welltok was alerted to the compromise on July 26, 2023, after investigating published vulnerabilities. The incident affected patients of Elixir Pharmacy. Welltok engaged third-party cybersecurity specialists, reconstructed systems, and is offering credit monitoring services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jul 26, 2023
Discovered
Dec 5, 2023
Filed
vs. sector median
+6 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.