Welltok, Inc. disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names, treatment information, diagnoses, provider names, patient IDs, and health insurance information. The incident was discovered on July 26, 2023. Welltok engaged third-party cybersecurity specialists and is offering 12 months of credit monitoring to affected individuals.