Data breach
OSF Healthcare
- Records
- 520,187
- Breach date
- 31 May 2023Estimated
- Added
- 4 December 2024
What was exposed
8 types of data · 1 more reported · 1 puts you at serious risk
- Doctors' names1
- Email addresses1
- Names1
- Home addresses1
- Insurance providers1
- Medical diagnoses1
- Phone numbers1
- Social security numbers1
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
OSF HealthCare, a large Illinois-based health system headquartered in Peoria, has been linked to a large data exposure stemming from the 2023 MOVEit file-transfer software attacks. The listing covers 520,187 records associated with the organization, with an estimated attack date of May 31, 2023. The incident did not involve OSF's own systems directly. Instead, the data was held by Welltok, Inc., a third-party vendor that operated a patient communication platform used by OSF and other healthcare organizations. Welltok used Progress Software's MOVEit Transfer product, which attackers exploited en masse starting in late May 2023, an campaign widely attributed to the Cl0p ransomware group.
Breach Timeline
May 30, 2023: According to Welltok's regulatory notices, an unauthorized party accessed the MOVEit server used by Welltok, one day before Progress Software publicly disclosed the vulnerability.
July 26, 2023: Welltok discovered the breach and determined that personal and health information may have been accessed and acquired through the MOVEit vulnerability.
September 22, 2023: Welltok notified OSF HealthCare System that it had been impacted, prompting OSF to investigate which of its patients were affected.
November 29, 2023: OSF HealthCare confirmed in a statement that it was impacted by the Welltok breach, as reported by the law firm Strauss Borrelli.
December 4, 2023: Welltok filed a notice with the Maine Attorney General and began mailing breach notification letters to affected individuals on behalf of its clients, including OSF HealthCare System.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers, email addresses, phone numbers, names, doctor names, home addresses, medical diagnoses, and insurance provider details.
Welltok's notice to state attorneys general described the full range of potentially exposed data more broadly. Depending on the individual, it may include names, dates of birth, addresses, phone numbers, email addresses, Social Security numbers, medical record numbers or patient identification numbers, treatment information, diagnosis information, provider names, prescription information, health insurance information, and treatment cost information.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of Social Security numbers, dates of birth, and health details is particularly sensitive. With this information, criminals can attempt to open lines of credit, file fraudulent tax returns, or impersonate victims in other ways. Medical data adds another layer of risk: diagnosis and treatment information can be used for medical identity theft, where someone receives care or bills insurance under another person's identity. That can corrupt medical records and create problems for victims when they seek treatment or submit insurance claims. Exposed email addresses and phone numbers also enable targeted phishing, including convincing scams that reference real medical details to appear legitimate. Affected individuals may also face risk from insurance-related fraud, since health insurance information was among the data types reported.
What Is OSF Healthcare Doing in Response?
OSF confirmed in late November 2023 that it was impacted by the Welltok incident. Because the data was held by Welltok, notification letters were sent by Welltok on behalf of its clients, including OSF HealthCare System, beginning in December 2023. Welltok stated that it offered credit monitoring services through Experian for twelve to twenty-four months, depending on state law, at no cost to affected individuals. Civil litigation related to the OSF-linked MOVEit exposure has also been reported by plaintiffs' firms. Details of any OSF-specific remediation were not independently confirmed as of the drafting of this article.
What Should You Do If You Were Affected?
If you received a notification letter from OSF HealthCare or Welltok, enroll in the offered credit monitoring before its expiration date.
Place a free fraud alert or security freeze with the three major credit bureaus: Equifax, Experian, and TransUnion.
Review your credit reports for accounts you do not recognize, and monitor explanations of benefits and insurance statements for care you did not receive.
Be cautious with unexpected emails, calls, or texts that reference your health care, and avoid clicking links or sharing personal information in response.
If you spot signs of medical identity theft, report it to your insurer and consider filing a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.
In the news
- Strauss Borrelli PLLC, OSF HealthCare Data Breach Investigationstraussborrelli.com (opens in a new tab)
- Welltok Inc. Notice of Data Event, Maine Attorney Generalmaine.gov (opens in a new tab)
- JD Supra, Welltok Announces Data Breachjdsupra.com (opens in a new tab)
- ID Strong, Welltok's MOVEit Breach Continuesidstrong.com (opens in a new tab)
