Confirmed breach. Intrusion Aug 1, 2024, discovered Aug 1, 2024 — the first regulatory filing landed 68 days later (flagged late). 23,082 individuals reported across the linked filings.
Wellfleet Group, LLC reported to HHS on 2024-10-08 a Unauthorized Access/Disclosure affecting 23,082 individuals. Breached information located on Network Server. A student made PHI (names, birthdates, diagnoses) viewable via the Internet. The CE implemented additional administrative, technical, and security safeguards.
Affected (this filing): 23,082
3 State AG filingsOct 11, 2024ExpandCollapse
VTMTCA
🍁Vermont State AGlinked via multistate filing link · 100%
31 days
🐻California State AGMost recentlinked via multistate filing link · 95%
Wellfleet Group, LLC experienced a data security incident due to a website misconfiguration that allowed medical referral data (PHI) to be indexed by search engines. The issue was discovered on August 1, 2024, and immediately remediated by disabling the misconfiguration and removing public access. No malicious cyber activity was involved. Affected individuals were offered 24 months of credit monitoring.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Wellfleet Group, LLC, a third-party administrator for student health insurance plans, disclosed a data security incident on October 11, 2024. On August 1, 2024, a website misconfiguration allowed deep-links to medical referral pages to be indexed by search engines without authentication. This exposed PHI including names, DOBs, and medical diagnoses. Wellfleet engaged third-party experts, fixed the misconfiguration, and offered 24 months of credit monitoring.
VT AG >45 bday
🦬Montana State AGlinked via same-victim cross-source · 100%
Wellfleet Group, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2024-10-11. The breach occurred on 8/1/2024. 16 Montana residents were affected.
Affected (this filing): 16
🐻California State AGlinked via same-victim cross-source · 100%
Wellfleet Group, LLC experienced a data security incident due to a website misconfiguration that allowed medical referral pages to be indexed by search engines without authentication. This exposed protected health information (PHI) including names, addresses, dates of birth, and diagnosis codes for students. The issue was discovered on August 1, 2024, and immediately contained by disabling the misconfiguration and removing indexed pages. No malicious cyber activity was involved. Affected individuals were offered 24 months of credit monitoring.