OSF Healthcare 2023.0 Data Breach

OSF HealthCare Catholic Health System Breach (2023): Patient Medical Diagnoses & SSN Exposed | ObscureIQ
ObscureIQ Breach Intelligence

Classification Tags

Cl0pThird-Party VendorMedicalEmail AddressFull NameMedical DiagnosisPhone NumberPhysical AddressSocial Security Number
High SeverityWebsite / service breach

OSF HealthCare Catholic Health System Breach (2023): Patient Medical Diagnoses & SSN Exposed

Catholic healthcare system operating hospitals and clinics.

Verified by ObscureIQ Intelligence
65/100Breach Risk Index
40Data Value
25Market Recency
581dSince Breach

Breach Intelligence Summary

Entity: OSF Healthcare · Actor: Cl0p · Sources: 2 references
Attack: Third-Party Vendor
Profile: Healthcare provider · Hospital and clinical services · Integrated health system · USA
Timeline: Breach (2023-05-31) · Year (2023.0)
Exposure: 520K records · 6 fields: Email Address, Full Name, Medical Diagnosis, Phone Number, Physical Address, Social Security Number
Status: Confirmed

Executive Summary

OSF HealthCare data was exposed in the 2023 Cl0p MOVEit campaign via its vendor Welltok, which used the vulnerable MOVEit Transfer platform. About 520,000 records were affected, including names, mailing and email addresses, phone numbers, dates of birth, genders, Social Security numbers, and National Provider Identifier (NPI) numbers.

ObscureIQ assessment: Severe risk. Enables identity theft, medical fraud, insurance abuse, and highly targeted health-related scams.

Breach Impact

SSNs combined with full identity and health-adjacent identifiers create serious identity-fraud and medical-fraud risk for patients.

About OSF Healthcare

OSF HealthCare is a US Catholic health system operating hospitals and clinics across Illinois and Michigan.

Why They Hold Your Data

Integrated healthcare systems collect patient identity, medical records, billing data, insurance information, and clinical interaction data across hospital networks.

Data Points Exposed

6 verified field types
Email Address
Full Name High
Medical Diagnosis Critical
Phone Number
Physical Address High
Social Security Number Critical

Field names are shown in full for clarity and search visibility. Canonical machine keys are emitted only in this page’s structured data.

Exploitation & Downstream Threats

Threat Activity:High
Primary downstream threats:
  • Identity theft and synthetic identity construction using government-issued IDs
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure
  • Medical identity fraud or insurance abuse using health data
Threat vectors:
  • Phishing, credential stuffing & account takeover
  • Name-based social engineering
  • Medical extortion, insurance fraud & discrimination
  • SIM swapping, vishing & SMS phishing
  • Physical stalking, mail fraud & identity verification
  • Home targeting, stalking & physical threat
  • Full identity theft & synthetic identity fraud

Threat Actor: Cl0p

Cl0p
Third-Party Vendor

Attribution and method are based on available breach intelligence. Reported attack vector: Third-Party Vendor.

Recommended Actions

If you believe your information may be included:

Protect Your ID Documents
Government-ID exposure enables document fraud — monitor and report misuse.
Enable MFA Everywhere
Turn on multi-factor authentication on email first, then financial accounts.
Report & Recover
If you spot misuse, start an official recovery plan and report fraud.

Frequently Asked Questions

What happened in the OSF Healthcare breach?

OSF HealthCare data was exposed in the 2023 Cl0p MOVEit campaign via its vendor Welltok, which used the vulnerable MOVEit Transfer platform. About 520,000 records were affected, including names, mailing and email addresses, phone numbers, dates of birth, genders, Social Security numbers, and…

What data was exposed?

Verified fields include Email Address, Full Name, Medical Diagnosis, Phone Number, Physical Address, Social Security Number.

What should I do if I was affected?

Change reused passwords, enable MFA, and (if identity or financial data is involved) freeze your credit and monitor your accounts.

Sources & References

Every claim on this page is traceable. This breach draws on:

Breach Index
DataBreach.com
Record & field corroboration
ObscureIQ Intelligence
ObscureIQ proprietary analysis
Risk Index scoring & downstream-threat assessment

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation