2023 Welltok (Virgin Pulse) — MOVEit Transfer compromise; multi-tenant health-plan notifications
Data compromised
Participant names, addresses, DOB, member IDs, SSN-class identifiers, and plan or wellness-program metadata per downstream notices
Technical writeup
Welltok, Inc.—the wellness-engagement vendor later positioned under Virgin Pulse—ran a Progress MOVEit Transfer instance that Clop-affiliated actors exploited in the late-May 2023 wave. Exfiltration from Welltok’s server drove a cascading HIPAA notification program affecting dozens of health-plan and employer clients; aggregated HHS-oriented reporting (e.g., HIPAA Journal rollups) cited on the order of 14.76 million individuals, with earlier press waves often citing roughly eight million, reflecting ongoing regulator tallies. Data elements varied by program but commonly included demographic, contact, and health-plan or clinical-administrative fields.
Root cause
CVE-class exploitation of MOVEit Transfer enabling mass exfiltration (Clop campaign context)