Wellfleet Group, LLC
ent_f35d0ff0bdf3bbb4159bf009
Disclosures
5
State AG · HHS OCR · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
23,082
nationwide · HHS OCR MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Wellfleet Group, LLC
- Normalized
- wellfleet group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🐻California State AGas victim2024-11-11
Wellfleet Group, LLC experienced a data security incident due to a website misconfiguration that allowed medical referral data (PHI) to be indexed by search engines. The issue was discovered on August 1, 2024, and immediately remediated by disabling the misconfiguration and removing public access. No malicious cyber activity was involved. Affected individuals were offered 24 months of credit monitoring.
- 🍁Vermont State AGas victim2024-10-11
Wellfleet Group, LLC, a third-party administrator for student health insurance plans, disclosed a data security incident on October 11, 2024. On August 1, 2024, a website misconfiguration allowed deep-links to medical referral pages to be indexed by search engines without authentication. This exposed PHI including names, DOBs, and medical diagnoses. Wellfleet engaged third-party experts, fixed the misconfiguration, and offered 24 months of credit monitoring.
- 🦬Montana State AGas victim2024-10-11
Wellfleet Group, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2024-10-11. The breach occurred on 8/1/2024. 16 Montana residents were affected.
- 🐻California State AGas victim2024-10-11
Wellfleet Group, LLC experienced a data security incident due to a website misconfiguration that allowed medical referral pages to be indexed by search engines without authentication. This exposed protected health information (PHI) including names, addresses, dates of birth, and diagnosis codes for students. The issue was discovered on August 1, 2024, and immediately contained by disabling the misconfiguration and removing indexed pages. No malicious cyber activity was involved. Affected individuals were offered 24 months of credit monitoring.
- MASSACHUSETTSHHS OCRas victim2024-10-08
Wellfleet Group, LLC reported to HHS on 2024-10-08 a Unauthorized Access/Disclosure affecting 23,082 individuals. Breached information located on Network Server. A student made PHI (names, birthdates, diagnoses) viewable via the Internet. The CE implemented additional administrative, technical, and security safeguards.