Healthcare provider · Hospital and clinical care services · Integrated health system · USA
Integrated healthcare system.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Mass General Brigham Health Plan was hit as part of the Cl0p ransomware group's 2023 campaign targeting Progress Software's MOVEit Transfer file transfer platform. Cl0p exploited a zero-day vulnerability in MOVEit to reach patient data held by Welltok, a health engagement and data analytics vendor used by the health plan. The breach exposed records for approximately 4.1 million patients, making it one of the larger incidents tied to that campaign. The exposed data included full names, home addresses, phone numbers, email addresses, and medical diagnoses. The combination of contact details and diagnosis information is particularly sensitive. It creates conditions for targeted phishing, insurance fraud, and medical identity theft, where criminals use someone else's information to obtain care or file false claims. The prestige of the Mass General Brigham name can also make impersonation scams more convincing to victims. Mass General Brigham notified affected patients and offered credit monitoring services following the breach. The health system is among the named parties in the consolidated MOVEit multidistrict litigation, a federal class action proceeding in the District of Massachusetts involving dozens of organizations affected by the same campaign. Affected individuals should remain alert to unsolicited contacts referencing their medical care, monitor their insurance statements for unfamiliar claims, and consider placing a credit freeze if they have not done so already.
Full threat analysis, exploitation vectors, and principal guidance below.
12 additional sections · verified field analysis · defensive doctrine
4.1M records analyzed
Mass General Brigham is a Boston-based integrated health system formed through the affiliation of Massachusetts General Hospital and Brigham and Women's Hospital, two of the most prominent academic medical centers in the United States. The system operates more than a dozen hospitals and hundreds of outpatient locations across Massachusetts and beyond, with a combined clinical, research, and education mission. It is affiliated with Harvard Medical School and consistently ranks among the top hospital systems in national quality assessments.
Integrated health systems collect patient identity, contact, insurance, billing, appointment, and clinical records across hospitals, specialty care, and administrative workflows.
Mass General Brigham has continued expanding its ambulatory care and community health footprint while managing cost pressures common across large academic health systems. The system has invested in digital health and research infrastructure. No major organizational changes beyond the breach context have been prominently reported in the recent period.
The 2023 incident was part of the Cl0p ransomware group's zero-day exploitation of Progress Software's MOVEit Transfer platform, accessed through Welltok — a health engagement and data analytics vendor used by Mass General Brigham Health Plan. The breach compromised patient data for approximately 4 million individuals including names, email addresses, phone numbers, home addresses, and medical diagnoses. Mass General Brigham notified affected patients, offered credit monitoring services, and reported the incident to relevant regulators. The system is a named party in the consolidated MOVEit multidistrict litigation in the District of Massachusetts, alongside dozens of other healthcare organizations caught in the same campaign.
• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Medical identity fraud or insurance abuse using health data
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A mature extortion group associated in public reporting with TA505 and FIN11-linked ecosystems. Cl0p is known for mass exploitation of managed file transfer products, including the 2023 MOVEit Transfer campaign exploiting CVE-2023-34362.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation