WVU Medecine 2023 Data Breach

WVU Medicine Academic Health System Breach (2023): 2.9 Million Patient Records Including Medical Diagnoses & SSN

Healthcare provider · Hospital and clinical services · Academic health system · USA

WVU Medicine Academic Health System Breach (2023): 2.9 Million Patient Records Including Medical Diagnoses & SSN

Academic health system affiliated with West Virginia University.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
76/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
2.9MRecords
2023Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
FinancialAccount Balance
PHI / MedicalMedical Diagnosis
AddressPhysical address
Classification Tags
Cl0p / CL0PWeb Application ExploitHealthcareMedicalPatients2023

Breach Summary

WVU Medicine, the academic health system affiliated with West Virginia University, suffered data breaches in 2023 through two third-party vendors. One incident involved unauthorized access to the ECHO Provider Services portal, exposing patient names and insurance details. A separate vendor breach was far broader in scope, ultimately compromising approximately 2.9 million records. The more extensive breach exposed a serious combination of personal, financial, and medical information: names, home addresses, email addresses, phone numbers, Social Security numbers, account balances, and medical diagnoses. This combination is particularly dangerous. Social Security numbers enable identity theft and fraudulent credit activity, while medical diagnoses paired with account balances can be used to craft highly targeted scams that exploit a patient's health condition or outstanding bills. WVU Medicine notified affected patients and reported both incidents to regulators as required under HIPAA, the federal law governing the privacy of patient health information. No major settlement or public enforcement action specific to these breaches has been documented. Affected individuals face elevated long-term risk of identity theft, medical fraud, and insurance abuse, and should closely monitor their credit reports, explanation-of-benefits statements, and any financial accounts for suspicious activity.

Full threat analysis, exploitation vectors, and principal guidance below.

12 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

2.9M records analyzed

About WVU Medecine

WVU Medicine is the academic health system affiliated with West Virginia University, operating hospitals, specialty clinics, and outpatient facilities across West Virginia and the surrounding region. Its flagship facility is J.W. Ruby Memorial Hospital in Morgantown. The system serves as the primary tertiary care provider for much of rural West Virginia and provides clinical training for WVU's health sciences programs.

Why They Hold Your Data

Healthcare systems and hospital networks aggregate patient identity, contact, billing, insurance, and diagnosis data across clinical and vendor-connected systems.

Recent Developments

WVU Medicine has continued expanding its clinical and community health services across West Virginia. The system has invested in rural health access and telehealth infrastructure to serve a dispersed patient population. No major organizational changes beyond the breach context have been prominently reported.

Data Points Exposed

7 verified field types
Account Balance High
Email Address
Full Name
Medical Diagnosis Critical
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

In 2023 WVU Medicine was affected by breaches through two third-party vendors. One involved unauthorized access to the ECHO Provider Services portal, compromising patient information including names and insurance details. A separate vendor incident resulted in more extensive exposure including account balances, email addresses, home addresses, phone numbers, Social Security numbers, and medical diagnoses across approximately 2.9 million records. WVU Medicine notified affected patients and reported the incidents to regulators. As a covered entity under HIPAA, the system's vendor oversight obligations were implicated by both incidents. No settlement or major enforcement action specific to these breaches has been prominently documented in public sources.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using government-issued IDs | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Medical identity fraud or insurance abuse using health data

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
  4. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  5. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
C/
Threat Actor: Cl0p / CL0PConfidence: High
Ransomware and mass exploitation group

Motivation: Financial extortion
A mature extortion group associated in public reporting with TA505 and FIN11-linked ecosystems. Cl0p is known for mass exploitation of managed file transfer products, including the 2023 MOVEit Transfer campaign exploiting CVE-2023-34362.

Read the full threat-actor profile →
This breach is linked to the MOVEit / Cl0p (2023) campaign (2023 related breaches tracked by ObscureIQ). See the full campaign analysis →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation