CVS
bd_c1b62916b13de301 · schema v1 · pii pii-v1
Full breach record for CVS →Welltok, Inc. reported a supplemental data event for the Blue Cross Blue Shield Federal Employee Program. An unknown actor exploited vulnerabilities in the MOVEit Transfer server on May 30, 2023, exfiltrating names, DOBs, and Medicare IDs. Welltok was alerted on July 26, 2023. Notices were sent to 4,479 Washington residents starting Jan 23, 2024. Credit monitoring via Experian was offered.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jul 26, 2023
Discovered
Apr 16, 2024
Filed
vs. sector median
+25 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.