Clustered 5 filings across 4 jurisdictions · filing window Jul 21, 2023 → Nov 3, 2023. View entity profile → Other incidents for this victim →
incident inc_c86759fc19634658 · merge_method llm · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
Identity (basic) · Government ID
MD ME MT VT
HHS OCR · State AG
Earliest sighting first · deep chronology in Litigation Timeline
May 28, 2023 → May 29, 2023
When the intrusion reportedly occurred, per the linked filings
May 30, 2023
Reported by VERMONT AG filing
Jun 22, 2023
Reported by MAINE AG, HHS OCR filings
Westat, Inc. reported to HHS on 2023-10-13 a Hacking/IT Incident affecting 51,513 individuals. A software application used by its business associate exposed PHI including names, addresses, dates of birth, claims information, diagnoses/conditions, and treatment information. Breached information located on a Network Server. The BA notified HHS and affected individuals, provided substitute notice, and offered complimentary credit monitoring services.
Affected (this filing): 51,513
Westat, Inc. reported to HHS on 2023-11-03 a Hacking/IT Incident affecting 20045 individuals. Breached information located on Network Server. A software application used by a business associate exposed PHI including names, addresses, DOB, claims, diagnoses, and treatment info. BA provided credit monitoring and enhanced safeguards.
Affected (this filing): 20,045
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Westat, Inc. notified consumers of a data breach involving its third-party vendor, Progress MOVEit. A zero-day vulnerability allowed unauthorized copying of data from a MOVEit server between May 28-29, 2023. Impacted data included names, dates of birth, and Social Security numbers. Westat engaged forensic specialists, applied patches, and offered credit monitoring services.
Westat, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-21. The breach occurred from 5/28/2023 to 5/29/2023. 68 Montana residents were affected.
Affected (this filing): 68
Westat, Inc. experienced an external system breach on May 29, 2023, which was discovered on June 22, 2023. The breach compromised the names and Social Security numbers of 7,954 individuals, including 65 residents of Maine. Affected individuals were notified on July 21, 2023, and offered 12 months of credit monitoring and identity protection services through IDX.
Affected (this filing): 65