Trending
STEUBENVILLE -- An unauthorized data access event experienced by a vendor of CommonSpirit Health, Trinity Health System's sponsoring organization, might have had an impact on the privacy of certain individual's information.
WellTok Inc., which develops information-sharing software for health care organizations, has begun sending notifications through the mail to individuals whose information could have been impacted. The event in question was a breach in Welltok's MOVEit Transfer tool server that occurred on May 30.
Affected information varies between persons and may include name and address, telephone numbers or e-mail address, as well as Social Security numbers, Medicare and Medicaid ID numbers or select health insurance information for a small group of individuals. Also included may be other individuals' health information, such as provider name, prescription name or treatment code.
A release on WellTok's website, welltok.com, lists more than 40 organizations with impacted individuals, among them being Trinity Health System. WellTok has said it does not have any evidence that the affected information has been misused.
"We take this event and the security of personal information in our care very seriously," WellTok states on its website. "Upon learning of this event, we moved quickly to investigate and respond to the event and notify potentially affected individuals. As part of our ongoing commitment to the security of information, we are reviewing and enhancing our existing policies and procedures related to data privacy to reduce the likelihood of a similar future event."
Clients of Trinity Health System will soon receive or might have already received a notification letter from WellTok describing the data event, WellTok's response and ways individuals can help protect their information, if desired.
A statement from Trinity Health System reads, "Because WellTok is a vendor of CommonSpirit Health, Trinity Health System's sponsoring organization, we want to ensure that anyone affected by the WellTok event follows processes to get the help and support they need. Again, this event is being reported by WellTok, not CommonSpirit Health or Trinity Health System."
In its letters, WellTok recommends that individuals "remain vigilant" against instances of fraud and identity theft by reviewing their account statements and monitoring free credit reports for errors and questionable activity.
WellTok notes in its letters that, under U.S. law, individuals are entitled to a single free credit report annually from each of the three major consumer report providers -- Equifax, TansUnion and Experian. WellTok provides contact information in its letter for the three agencies so individuals can request a free copy of their credit report, place a fraud alert or place a security freeze. A free credit report can also be ordered by visiting annualcreditreport.com or by calling WellTok's toll-free, dedicated assistance line at (877) 322-8228.
Individuals are entitled to place a one-year or an extended fraud alert on a credit file at no cost, WellTok says. Businesses that see a fraud alert on a credit file must verify the individual's identity before extending new credit. Victims of identity theft qualify for an extended fraud alert, which lasts seven years.
Trinity Health System's release adds, "Those with questions or who need additional support can follow the directions on (WellTok's) letter or call (800) 628-2141."
WellTok says it was first alerted of an earlier, alleged compromise to its MOVEit Transfer server on July 26. WellTok installed all available security upgrades to the server, in connection with "vulnerabilities" made public by the MOVEit Transfer tool's developer. It also examined its systems to determine the vulnerabilities' possible impact and ultimately determined at the time that there had been no compromise.
Continued investigations with third-party cybersecurity specialists led to the discovery of "additional information" on possibly hidden vulnerabilities, WellTok says, adding that a full system and historical data reconstruction on Aug. 11 "determined … that an unauthorized actor exploited software vulnerabilities, accessed the MOVEit Transfer server on May 30 … and exfiltrated certain data from the MOVEit Transfer server during that time.
"Welltok subsequently undertook a time-consuming and detailed reconstruction and review of the data stored on the server. … Subsequently, on Aug. 26, … Welltok learned that data related to certain individuals was present on the impacted server at the time of the event."