CRITICAL SEVERITYMedical

WVU Medecine Data Breach

WVU Medicine Academic Health System Breach (2023): 2.9 Million Patient Records Including Medical Diagnoses & SSN

Academic health system affiliated with West Virginia University.

Verified by ObscureIQ Intelligence

10.0Severity
2.9MRecords
7Fields
2023Year

ObscureIQ Breach Intelligence Scores
0.0
Breach Risk Index
63
Data Value
0
Market Recency
0
days
Since Breach

Risk Interpretation

Severe risk. The combination of SSNs, home addresses, account balance data, and medical diagnosis supports identity theft, medical fraud, insurance abuse, and highly targeted scams exploiting health status or unpaid balances.

🎯 Impact & Downstream Threats

In 2023 WVU Medicine was affected by breaches through two third-party vendors. One involved unauthorized access to the ECHO Provider Services portal, compromising patient information including names and insurance details. A separate vendor incident resulted in more extensive exposure including account balances, email addresses, home addresses, phone numbers, Social Security numbers, and medical diagnoses across approximately 2.9 million records. WVU Medicine notified affected patients and report

Primary downstream threats:
  • Identity theft and synthetic identity construction using government-issued IDs
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure
  • Medical identity fraud or insurance abuse using health data

🔓 Threat Vectors

High-value targeting
Phishing, credential stuffing & account takeover
Name-based social engineering
Medical extortion, insurance fraud & discrimination
SIM swapping, vishing & SMS phishing
Physical stalking, mail fraud & identity verification
Home targeting, stalking & physical threat
Full identity theft & synthetic identity fraud

📋 Breach Intelligence

EntityWVU Medecine (WVU Medicine)
OrganizationAcademic Healthcare System • USA
Breach Date2023-05-31
DBC Added2024-12-04
Records~2.9M (2,889,130 records)
Attack VectorUnauthorized Access
Data SubjectsPatient
Breach PathwaySupply_Chain:Vendor
SourceDataBreach.com / ObscureIQ
SensitivityRestricted
Breach ID1494.0
StatusConfirmed

📝 Executive Summary

WVU Medicine, the academic health system affiliated with West Virginia University, suffered data breaches in 2023 through two third-party vendors. One incident involved unauthorized access to the ECHO Provider Services portal, exposing patient names and insurance details. A separate vendor breach was far broader in scope, ultimately compromising approximately 2.9 million records. The more extensive breach exposed a serious combination of personal, financial, and medical information: names, home addresses, email addresses, phone numbers, Social Security numbers, account balances, and medical diagnoses. This combination is particularly dangerous. Social Security numbers enable identity theft and fraudulent credit activity, while medical diagnoses paired with account balances can be used to craft highly targeted scams that exploit a patient's health condition or outstanding bills. WVU Medicine notified affected patients and reported both incidents to regulators as required under HIPAA, the federal law governing the privacy of patient health information. No major settlement or public enforcement action specific to these breaches has been documented. Affected individuals face elevated long-term risk of identity theft, medical fraud, and insurance abuse, and should closely monitor their credit reports, explanation-of-benefits statements, and any financial accounts for suspicious activity.

🏢 About WVU Medecine

WVU Medicine is the academic health system affiliated with West Virginia University, operating hospitals, specialty clinics, and outpatient facilities across West Virginia and the surrounding region. Its flagship facility is J.W. Ruby Memorial Hospital in Morgantown. The system serves as the primary tertiary care provider for much of rural West Virginia and provides clinical training for WVU's health sciences programs.

Healthcare provider | Hospital and clinical services | Academic health system | USA
Academic Healthcare SystemUSAwvumedicine.org

🗂 Why They Hold Your Data

Healthcare systems and hospital networks aggregate patient identity, contact, billing, insurance, and diagnosis data across clinical and vendor-connected systems.

📰 Recent Developments

WVU Medicine has continued expanding its clinical and community health services across West Virginia. The system has invested in rural health access and telehealth infrastructure to serve a dispersed patient population. No major organizational changes beyond the breach context have been prominently reported.

🔍 Data Points Exposed

7 verified field types:
Social Security Number
Email
Phone Number
Account Balance
Name
Home Address
Medical Diagnosis

Exposure Categories

CredentialsSSN
LocationPHYS ADDR
MedicalDIAGNOSIS

Canonical Fields

account_balance, email_address, full_name, medical_diagnosis, phone_number, physical_address:home, ssn

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~2.9M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: wvumedicine.org-2024

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of WVU Medecine
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

Unauthorized AccessMedicalEmailPhoneAddress

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom