DisclosureLens
HackingHealthcareTechnologyHealthcareVulnerability ExploitStolen CredentialsData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedN-DayIdentity (basic)LowContained

Elixir Pharmacy

bd_b8f67070c4cc8147 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 26, 2023

Filed

Dec 5, 2023

To disclose

19 weeks

Affected

Not disclosed

Confidence

64%
Full breach record for Elixir Pharmacy

Welltok, Inc., a service provider for Elixir Pharmacy, disclosed that an unknown actor exploited software vulnerabilities in a MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. Welltok was alerted to the compromise on July 26, 2023, after investigating published vulnerabilities. The incident affected patients of Elixir Pharmacy. Welltok engaged third-party cybersecurity specialists, reconstructed systems, and is offering credit monitoring services to affected individuals.

California clockDiscovered Jul 26, 2023Notified Dec 4, 2023131d CA 60-day late19 weeks discovery → filing

Incident timeline

undetected · 57 days
discovery → filing · 19 weeks / 132 days

May 30, 2023

Begins

Jul 26, 2023

Discovered

Dec 5, 2023

Filed

vs. sector median

+6 wks slower

Part of Welltok supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.