- The top hospitals by state, per Forbes
- Dentists could soon play a larger role in vaccine administration: Research
- 8 behavioral health layoffs to know | 2026
- 19 new behavioral health projects to know
- Humana to exit Medicare Advantage plans covering 600,000 members in 2027
- Inside Inova’s 46% release fill rate: Turning open OR time into more cases
- 26 new behavioral health study findings to know
- Why solo dentistry could soon be on the way out
- The survival test for provider-sponsored health plans
- CMS finalizes payment rules for inpatient psychiatric, skilled nursing facilities: 12 things to know
- Feds’ ER records request leaves systems in limbo
- Qilin ransomware racks up 168 healthcare victims
- Inside UVM Health’s affordability-centered response to a $220M revenue hit
- The 5 biggest health system layoffs in 2026
- FTC sues Hims & Hers over health data sharing, billing practices
- Real estate firm acquires newly built ASC in Wisconsin
- California urology group joins PE-backed Unio
- Dental school debt vs. medical school debt: 4 stats
- Children’s Hospital Los Angeles appoints Dr. Andrew Costandi as anesthesiologist-in-chief
- FTC sues Hims & Hers over data privacy, billing practices
- GEICO accuses 2 NYC physician groups of $2M fraud scheme
- MOB deal activity dropped $655M in Q2: 6 things to know
- How this North Carolina surgeon dodged a $2M ASC build-out
- ‘You can’t out-recruit a retention problem’: Inside dentistry’s labor crisis
- The shifting dental payer landscape
- New York City dental practices named in deceptive treatment financing lawsuit
- The ChatGPT, health tech vendor reckoning
- Oregon psychiatric hospital cuts 34 beds, to lay off 45 employees
- Who’s buying up spine practices?
- 15 rising stars in orthopedic surgery
- CMS' proposed 340B reimbursement cut—who wins, and who loses?
- American Gastroenterological Association CEO to retire after 12 years
- Virtual care helps patients improve their gambling disorder symptoms, Birches Health finds
- Texas DSO hit with cyberattack affecting 30,000 individuals
- How 3 Connecticut hospitals responded to rising psychiatric ED demand
- Nuvia Dental Implant Center to open in Texas
- Specialty1 Partners enters joint venture with Ohio periodontal practice
- Federal judge halts mental health grant terminations, again: 7 notes
- Acadia reports $10.9M Q2 profit, down 64% year over year
- CMS ending Medicare Part D subsidy program
- Red Cross Declares Rare National Blood Supply Crisis Amid Summer Shortfall
- Not Just Pregnancy Fatigue: Could It Be Sleep Apnea?
- More Women Drinking During Pregnancy
- HHS launches behavioral health pledge as Optum preps new services
- Wellstar Health System lays off 761 corporate, administrative staff
- Biogen flips '26 guidance from expected decline to sales increase
- Teva’s innovation engine offsets generics slump, leaving one analyst ‘shocked’ by Ajovy’s surge
- Talking To Your Baby? Eye Contact Is Key To Language Development, Experiment Shows
- Boosted by CMS settlement, Incyte expects Opzelura to cross $1B in 2026
- Leapfrog launches expanded ASC public reporting program
- Cyclospora Boosts Fears That Deadlier Foodborne Outbreaks Are Ahead
- DoorDash, GrubHub Delivering Junk Food To 1 In 4 Teens During School Hours
- Trump Has Quietly Throttled an Agency Devoted to the Safety of American Healthcare
- Uninsured but Undaunted, a Surgical Patient Searched the Globe for a Deal
- Hospice’s Bad Reputation Amid Fraud Crisis Will Hurt Patients, Industry Experts Warn
- A look at CVS’ march toward a simpler patient experience
- Humana plans more market exits for 2027, CFO says
- PMCPA sanctions melatonin drugmaker over misleading information
- The high stakes of pediatric dental sedation: Understanding the clinical and legal risks facing pediatric dentists
- AI doctor startup Doctronic acquires Summer Health to move into pediatric care
- Autistic patients less likely to receive on-time cancer screening: Study
- Rare disease foundation partners with Citizen Health to embed AI agent into everyday care
- Community Medical’s CEO on Medicaid cuts: ‘It’s not something that keeps me up at night’
- AI, energy prices will strain hospitals' non-labor spending in 2027: Vizient
- CG Life embraces next-gen era in merger with AI-native agency The Considered+AI
- How 2 FDA citations complicate Hengrui, Elevar’s push for liver cancer combo approval
- American Red Cross declares second-ever national blood supply crisis, urges ‘immediate’ donations
- Fifth Death Reported In NYC Legionnaires' Disease Outbreak
- Universal Health Services tops Q2 expectations, but dials back full-year earnings
- Many Young Adults Aren't Ready To Manage Their Own Healthcare, Poll Finds
- Can A Daily Multivitamin Help You Stay Active As You Age?
- With $5.5B settlement offer, J&J could be on its way to resolving talc litigation
- Prebiotic Soda Health Claims Questioned In New Nutrition Study
- Family-Based Childhood Obesity Program Helps Kids Cut Weight, Become Healthier
- To Afford Aging In Place, Older Adults Turn To 'Golden Girls' Housing
- Breakfast Can Help Teens Make Better Food Choices Throughout Their Day, Study Says
- GSK CEO targets $2.5B in cost savings from mature products, procurement, supply chain
- Newsom Reverses on Long-Sought Paid Leave Benefit for Teachers in California
- Federal Loan Caps Add Barriers — And Likely Debt — for Healthcare Students
- Cyclospora Boosts Fears That Worse Foodborne Outbreaks Are Ahead
- Margin improvements underpin Centene's strategy for 2027 ACA plans, CEO says
- Baxter issues recall of antibiotic IV bags after bits of cardboard flagged in solution
- Havas Lynx revamps New York C-suite 16 months after last shakeup
- LifeBridge Health deploys Prenosis' FDA-authorized AI tool to speed sepsis detection
- Included Health inks agreement to acquire Firefly Health to scale alternative health plans for employers
- Gilead uses humor, relatability in ‘Up to Date’ HIV prevention push
- FDA Panel Backs Two Peptides For Compounding, Rejects One
- Aurenar lands $5.7M seed funding round for non-invasive neuromodulation platform
- Industry survey finds MA enrollees have lower out-of-pocket costs than those in traditional Medicare
- How Accurate Are Photo-Based Calorie Apps? 4 Are Put To The Test
- Procode AI secures $10M series A for AI-powered RCM for surgical billing
- Intermountain Health acquiring interests in 2 Idaho hospitals for $795M
- Sarepta taps AbbVie, Tessera vet Severino to write Duchenne firm's next chapter
- FDA approves Otsuka’s ADHD drug Simtriyo, teeing up its ‘next major CNS launch’
- On 4th try, Outlook scores FDA nod for reformulated version of Roche's Avastin for AMD
- AZ stays on track for $80B revenue goal as cancer meds, rare disease sales help offset Ultomiris miss
- Popular School Cafeteria Meals Need An Update To Meet Healthy Food Standards, Researchers Say
- Ovarian Syndrome Quadruples Heart Disease Risk In Women, Major Study Concludes
- Weed-Killing Chemical, Glyphosate, Linked To Premature Births In Humans, Study Says
- Legend Biotech CEO abruptly steps down without permanent replacement
- 'The Child Is Terrified': Doctors On Front Lines Of Measles Comeback Speak Out
- 'Yo-yo' Weight Loss Linked To Decline In Muscle Mass
- Trump Administration Demands Hospitals Share Emergency Room Records
- Tracking State Rural Health Transformation Plans
- As AI scribe adoption grows, researchers at Suki challenge the industry's quality playbook
- Journalists Assess Risks of Tick Bites, Wildfire Smoke, Rising Health Costs
- Salesforce lands $1.6B Veteran Affairs deal to integrate AI into healthcare workflows
- FDA Advisers Dismiss Safety Warnings, Back Four Peptide Treatments
- Frequent Marijuana Use Linked To Higher Stress Hormone Levels
- Peptide adcomm Day 2: Emideltide voted down in panel's 1st pushback
- Novo escalates Lilly false advertising suit with planned bid to halt comparative ads
- Amgen hands in data package in hopes of FDA hearing for Tavneos defense
- Another setback for Ipsen's Albireo portfolio as Bylvay flunks phase 3 trial
- Flourish Health secures $26M to scale intensive youth mental healthcare
- Back Pain? Try Swimming, Study Says
- Ozempic Cuts Down Calorie Intake For At Least A Year, Even If Hunger Returns, Trial Finds
- Money Problems Might Make Your Brain Old Before Its Time, Study Suggests
- Merck stages expanded access to monthly HIV PrEP pill ahead of approval
- Black MS Patients Dying Younger Than White Ones, Study Finds
- Public Health Improvements Stall Amid Trump's DEI Crackdown
- To Afford Aging in Place, Older Adults Turn to ‘Golden Girls’ Housing
- Gastroenterologists flag clinical remission and its durability as unmet needs in IBD care: survey
- Many U.S. Schools Unprepared To Help Concussed Students Return To The Classroom
- Nearly 1.6 Million Dozen Eggs Pulled From Shelves Over Salmonella Concerns
- Organized Sports Help Enhance Motor Skills In Children With Autism
- People Living Longer, But Spending More Years With Illness And Disability
- Exercise Underwhelms As A Hip Arthritis Treatment, Review Concludes
- Tongue Pacemaker Might Improve Sleep Apnea Patients' Health
- Poll: Costs Are Top Health Care Issue For Midterm Voters, But Fraud Tops GOP List
- Measles Cases Set 35-Year US Record With Months To Go In 2026
- Taylor Farms Faces Cyclospora Outbreak, Recalls And Political Questions
- Headstands and Summervaults: A Statement on Crypto Vaults and Lending Strategies
- GLP-1 Use Surges Among Young People With Obesity
- 1 In 4 Americans Stuck In Jobs For Health Insurance, Survey Finds
- How Does ADHD Affect Athletes' Concussion Risk?
- TV Does Indeed Rot Your Brain, Study Says
- HaloMD's Patrick Velliky explains why No Surprises Act IDR enforcement matters
- The CSO Model Is Endangered. Here’s How Contract Field Organizations Must Evolve to Survive.
- Remarks at the Small Business Capital Formation Advisory Committee Meeting
- Seeking Public Comment on Seeking Public Capital: Remarks Before the Small Business Capital Formation Advisory Committee
- Remarks to the Small Business Capital Formation Advisory Committee
- Statement on Regulation E-Delivery
- Paper Taper: Statement on Proposed Regulation E-Delivery
- Statement on Proposed Regulation E-Delivery
- Remarks before the American-Hellenic Chamber of Commerce
- Remarks at the Society for Corporate Governance Conference
- Zimmer Biomet to Hire 500 in India as New Bengaluru Technology Centre Drives AI and MedTech Innovation
- AdaptHealth Investigates Data Breach After Social Engineering Attack, Possible Link to ShinyHunters Emerges
- Statement on the 2026 Regulatory Agenda
- Applying Agentic AI to Healthcare Delivery: The Key to True Transformation
Michigan healthcare freedom community forum
More than one million Michiganders' data were were stolen in a cybersecurity breach at a Corewell Health contractor, Welltok, Inc. About 8 million Americans' records in total were exposed in this breach.
Welltok is an SaaS (software as a service) company which provides communication services for Corewell Health's southeastern Michigan operations and a portal for Priority Health, among many other healthcare companies across America.
Welltok data breach exposes data of 8.5 million US patients
By Bill Toulas - November 22, 2023Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients in the U.S. after a file transfer program used by the company was hacked in a data theft attack.
Welltok works with health service providers across the U.S., maintaining online wellness programs, holding databases with personal patient data, generating predictive analytics, and supporting healthcare needs like medication adherence and pandemic response.
Earlier this year, the Clop ransomware gang exploited a zero-day vulnerability in the MOVEit software to breach thousands of organizations worldwide, following up with extortion demands and data leaks impacting over 77 million people.
Welltok published a notice of a data incident in late October, warning that its MOVEit Transfer server was breached on July 26, 2023. This occurred despite applying the security updates as soon as those were made available by the vendor.
Patient data was exposed during the breach, including full names, email addresses, physical addresses, and telephone numbers. For some, it also includes Social Security Numbers (SSNs), Medicare/Medicaid ID numbers, and certain Health Insurance information.
The impact of the breach impacted institutions in various states, including Minnesota, Alabama, Kansas, North Carolina, Michigan, Nebraska, Illinois, and Massachusetts, with the following healthcare providers said to be impacted:
- Blue Cross and Blue Shield of Minnesota and Blue Plus
- Blue Cross and Blue Shield of Alabama
- Blue Cross and Blue Shield of Kansas
- Blue Cross and Blue Shield of North Carolina
- Corewell Health
- Faith Regional Health Services
- Hospital & Medical Foundation of Paris, Inc. dba Horizon Health
- Mass General Brigham Health Plan
- Priority Health
- St. Bernards Healthcare
- Sutter Health
- Trane Technologies Company LLC and/or group health plans sponsored by Trane Technologies Company LLC or Trane U.S. Inc.
- The group health plans of Stanford Health Care, of Stanford Health Care, Lucile Packard Children’s Hospital Stanford, Stanford Health Care Tri-Valley, Stanford Medicine Partners, and Packard Children’s Health Alliance
- The Guthrie Clinic
Initial estimates about the number of impacted individuals varied as Welltok didn’t immediately disclose this information.
However, earlier today, the firm reported on the U.S. Department of Health and Human Services breach portal that the data breach has been confirmed to impact 8,493,379 people.
This figure places the Welltok breach as the second largest MOVEit data breach after services contractor Maximus, whose data breach affected 11 million people.
AG Dana Nessel is now involved:
Corewell Health Data Breach Exposes Info of One Million Michigan Patients
December 01, 2023
LANSING – A cybersecurity breach at Welltok, Inc., the software company contracted to provide communications services to Corewell Health’s southeastern Michigan properties, has reportedly affected more than one million Michigan residents, Attorney General Dana Nessel announced.The names, dates of birth, email addresses, phone numbers, medical diagnoses, health insurance information, and Social Security numbers for about one million Corewell Health patients were compromised in the breach. In addition, the names, addresses, and health insurance identification numbers of 2,500 users of the healthy lifestyle portal for Priority Health, an insurance plan owned by Corewell, were also compromised, according to a statement from the health system earlier this month. In total, the breach affected nearly 8.5 people nationally.
The attack, which occurred on May 30, exploited software vulnerabilities on the MOVEit Transfer server owned by Virgin Pulse, Welltok's parent company.
“Health information is some of the most personal information that we have,” said Nessel. “If there was ever data that required heightened cybersecurity measures, it is the information held by the healthcare sector. This kind of breach has occurred too often, and patients deserve to feel confident that their health data is protected in the most robust way possible. My office remains committed to helping Michigan residents keep their data private and secure.”
Welltok has confirmed that those affected include people who have received health care or insurance provided by the following companies:
- Asuris Northwest Health
- BridgeSpan Health
- Blue Cross and Blue Shield of Minnesota and Blue Plus
- Blue Cross and Blue Shield of Alabama
- Blue Cross and Blue Shield of Kansas
- Blue Cross and Blue Shield of North Carolina
- Faith Regional Health Services
- Hospital & Medical Foundation of Paris, Inc. dba Horizon Health
- Mass General Brigham Health Plan
- Regence BlueCross BlueShield of Oregon
- Regence BlueShield
- Regence BlueCross BlueShield of Utah
- Regence Blue Shield of Idaho
- St. Bernards Healthcare
- Sutter Health
- Trane Technologies Company LLC and/or group health plans sponsored by Trane Technologies Company LLC or Trane U.S. Inc.
- The group health plans of Stanford Health Care, of Stanford Health Care, Lucile Packard Children’s Hospital Stanford, Stanford Health Care Tri-Valley, Stanford Medicine Partners, and Packard Children’s Health Alliance
- The Guthrie Clinic
According to the HIPAA Journal, this cyberattack marks the fourth-largest healthcare data breach in the U.S. this year. The U.S. Department of Health and Human Services reported that data breaches among healthcare organizations more than doubled from 2019 to 2021. In 2022, at least 28.5 million healthcare records were breached nationwide.
Michigan, in particular, has experienced a surge in healthcare-related cyberattacks. In recent months, Attorney General Nessel notified Michigan residents about a ransomware attack affecting 2.5 million McLaren Health Care patients. Similarly, the University of Michigan faced a cyberattack in late August, leading to the compromise of personal information, including Social Security numbers, driver’s license or other government-issued ID numbers, and medical records.
If Welltok has a valid mailing address on file, the company is mailing a notice letter to individuals whose information was determined to be in the affected files. Anyone who does not receive a notice letter but would like to know if they are affected, or has other questions, may call the Welltok dedicated assistance line at 800-628-2141.
Although potentially impacted individuals should be receiving a notice letter from Welltok, state law does not currently require companies who experience a data breach to share that information with the Department of Attorney General. The Department often learns about these data breaches through media reports. The AG strongly recommends the legislature – similar to many other states – strengthen our law to require companies who experience a data breach to immediately inform the Department of Attorney General. This will allow the Attorney General to more quickly alert the public.
“Michigan simply must catch up to the states that require Attorney General notification of these significant breaches,” added Nessel. “To fulfill our duties of consumer protection and corporate oversight, the Department of Attorney General must be alerted to these breaches, when personal health and identifying information that is so often used to commit identity crimes, is compromised and made unsecure.”
The Department of Attorney General’s Data Breaches: What to do Next alert provides consumers with useful information about what kind of information can be accessed during a data breach.
To file a complaint with the Attorney General, or get additional information, contact:
Consumer Protection Team:
P.O. Box 30213
Lansing, MI 48909
517-335-7599
Fax: 517-241-3771
Toll-free: 877-765-8388
Online complaint formYour connection to consumer protection is just a click or phone call away. The Department provides a library of resources for consumers to review anytime on a variety of topics.
Typo alert for the AG's office.
In total, the breach affected nearly 8.5 people nationally.
Data for over 1 million Michiganders, Corewell Health patients compromised after massive Welltok cyber attack
By Cassandra Llamas Fossen, 2 days ago
(WWJ) - Roughly 1 million Michiganders were impacted after a cyber security breach was discovered at Welltok Inc., a healthcare software-as-a-service company contracted by Corewell Health.
Welltok recently notified over 8 million Americans on behalf of 20 healthcare providers and plans, including Corewell Health, of the data breach stemming from the May 2023 MOVEit hack, stating an unauthorized individual was able to view and exfiltrate sensitive information.
Priority Health -- a Corewell-owned insurance plan -- was also impacted, with data for 2,500 Priority members exposed.
The cyber attack is one of the largest breaches reported to the U.S. Department of Health and Human Services (HHS) so far this year.
According to Welltok, the hackers were able to take advantage of a vulnerability in Progress Software’s MOVEit Transfer server. The company said it immediately patched the vulnerability when it was found on May 31 and made any necessary security upgrades.
While Welltock conducted an examination into the incident, it wasn't until Aug. 11 when a third-party company hired to reconstruct its systems and historical data discovered the breach.
A letter was sent out earlier in November to the 8,493,379 people affected by the massive breach.
“We take this event and the security of personal information in our care very seriously. Upon learning of this event, we moved quickly to investigate and respond to the event and notify potentially affected individuals,” Welltok stated.
Names, addresses, email addresses, and phone numbers, including a small amount of Social Security numbers, health insurance information, and Medicare/Medicaid ID numbers were all reported to have been impacted.
“As part of our ongoing commitment to the security of information, we are reviewing and enhancing our existing policies and procedures related to data privacy to reduce the likelihood of a similar future event," Welltok said.
"While we have no evidence that any of your information has been misused, we are notifying you and providing information and resources to help protect your personal information," Welltok said in a statement.
Welltok opened a dedicated assistance line at 800-628-2141 to help patients who may have questions about the incident.
The company recommended credit monitoring for those affected by the breach.
Get MHF Insights
News and tips for your healthcare freedom.
We never spam you. One-step unsubscribe.






















