DisclosureLens
HackingHealthcareTechnologyHealthcareVulnerability ExploitCapture Stored DataData ExfiltratedTargetedIdentity (basic)Government IDPHIHealth (basic)HighContained

CVS

bd_c1b62916b13de301 · schema v1 · pii pii-v1

Severity

High

Discovered

Jul 26, 2023

Filed

Apr 16, 2024

To disclose

38 weeks

Affected

4,479state residents only

Confidence

69%
Full breach record for CVS

Welltok, Inc. reported a supplemental data event for the Blue Cross Blue Shield Federal Employee Program. An unknown actor exploited vulnerabilities in the MOVEit Transfer server on May 30, 2023, exfiltrating names, DOBs, and Medicare IDs. Welltok was alerted on July 26, 2023. Notices were sent to 4,479 Washington residents starting Jan 23, 2024. Credit monitoring via Experian was offered.

Washington clock WA AG >90d38 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 57 days
discovery → filing · 38 weeks / 265 days

May 30, 2023

Begins

Jul 26, 2023

Discovered

Apr 16, 2024

Filed

vs. sector median

+25 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4,479 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.