Centra Care 2023 Data Breach

Centra Care Urgent Care Network Breach (2023): 782K Patient Records Including Medical Diagnoses Exposed

Healthcare Provider · Urgent care and walk-in medical services · Urgent care clinic network · USA

Centra Care Urgent Care Network Breach (2023): 782K Patient Records Including Medical Diagnoses Exposed

CentraCare - Minnesota regional healthcare network.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
54/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
782KRecords
2023Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
FinancialAccount Balance
PHI / MedicalMedical Diagnosis
AddressPhysical address
Classification Tags
Cl0p / CL0PRansomware / ExtortionHealthcareMedicalPatients2023

Breach Summary

CentraCare Health, a Minnesota-based regional healthcare network operating hospitals, clinics, and the Centra Care urgent-care service line in central Minnesota, was drawn into the broader 2023 MOVEit supply-chain attack carried out by the Cl0p ransomware group. The attack occurred on or around May 30 to 31, 2023 when Cl0p exploited a previously unknown zero-day vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer file-sharing platform. CentraCare patient data was held by Welltok, a Virgin Pulse-owned patient engagement vendor that used MOVEit Transfer for large-dataset transfers between Welltok and its health-plan and provider clients. Welltok confirmed the breach in late October 2023. The breach affected approximately 782,000 CentraCare-attributed records based on records indexed by breach-tracking services, as part of a broader Welltok-wide breach affecting approximately 14.7 million individuals across multiple healthcare clients. Compromised fields for CentraCare patients included names, home addresses, email addresses, phone numbers, account-balance information, and medical diagnosis information. No Social Security numbers or payment-card numbers were included in the CentraCare-specific portion of the data, though other Welltok client portions did include SSN exposure. For affected CentraCare patients, the practical risk profile combines identity-fraud exposure with medical-context-specific risks. The combination of name, address, contact information, and medical diagnosis is a strong base for medical-themed phishing referencing real diagnoses, prescription-fraud attempts, and insurance-fraud claims billed under affected patients' identities. The inclusion of account-balance data adds direct billing-fraud risk because attackers may reference real outstanding balances to lend credibility to scams. Affected patients should remain alert to unsolicited contact referencing CentraCare, Welltok, or specific medical conditions, and should monitor health-insurance statements closely. Patients should also be aware that they may have been affected by additional unrelated breaches given the multi-vendor nature of healthcare supply chains.

Full threat analysis, exploitation vectors, and principal guidance below.

12 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

782K records analyzed

About Centra Care

CentraCare Health, often referred to in operations as Centra Care for its urgent-care service line, is a Minnesota-based regional nonprofit healthcare network headquartered in St. Cloud, Minnesota. The system operates a network of hospitals, primary-care clinics, urgent-care clinics, surgery centers, and home-health services across central Minnesota. The Centra Care urgent-care brand operates walk-in and outpatient medical services as one of CentraCare Health's service lines. As a HIPAA-regulated regional health system at substantial scale, CentraCare maintains comprehensive protected health information including patient identity, insurance, billing, diagnostic, treatment, and prescription records across hospital, clinic, urgent-care, and home-care operations.

Why They Hold Your Data

Urgent-care clinic networks collect patient identity, contact, insurance, billing, appointment, and treatment records across walk-in and outpatient care workflows.

Recent Developments

The 2023 MOVEit-related disclosure was one of multiple Welltok-related breach notifications affecting CentraCare's patient engagement processes. CentraCare initially issued a brief public statement attributing the exposure to an unnamed third-party vendor, with limited detail on the number of affected patients or remediation. Privacy advocates and journalists criticized the opacity of the disclosure and the limited credit-monitoring offer typical of MOVEit-related notifications. The MOVEit incident has been subsumed into the consolidated In re MOVEit Customer Data Security Breach multidistrict litigation, in which CentraCare could be named through discovery as the chain-of-custody for stolen files is established. Welltok's parent Virgin Pulse remains a primary defendant in the MDL.

Data Points Exposed

6 verified field types
Account Balance High
Email Address
Full Name
Medical Diagnosis Critical
Phone Number
Physical address High

Breach Impact

The institutional impact on CentraCare is meaningful given the size of the affected population and the public-trust consequences of the limited initial disclosure. Federal HIPAA notification obligations through Welltok as the business associate, an active Office for Civil Rights review covering Welltok and its covered-entity clients, multistate attorney-general filings, and the consolidated MOVEit multidistrict litigation are all underway. The vendor-pathway nature of the breach raises broader supply-chain governance questions for CentraCare's procurement and security functions. The reputational impact concentrates within central Minnesota where CentraCare is the dominant regional health system and patient retention is unusually consequential. Operationally, CentraCare's own systems were not directly compromised, which has helped contain disclosure obligations and remediation costs.

Exploitation & Downstream Threats

• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Medical identity fraud or insurance abuse using health data

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
C/
Threat Actor: Cl0p / CL0PConfidence: High
Ransomware and mass exploitation group

Motivation: Financial extortion
A mature extortion group associated in public reporting with TA505 and FIN11-linked ecosystems. Cl0p is known for mass exploitation of managed file transfer products, including the 2023 MOVEit Transfer campaign exploiting CVE-2023-34362.

Read the full threat-actor profile →
This breach is linked to the MOVEit / Cl0p (2023) campaign (2023 related breaches tracked by ObscureIQ). See the full campaign analysis →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation