Healthcare provider · Hospital and clinical care services · Integrated health system · USA
Healthcare system and provider.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In late May 2023, the Cl0p ransomware gang exploited a zero-day in Progress Software’s MOVEit Transfer platform (CVE-2023-34362) to steal data from Sutter Health’s patient-engagement vendor Welltok (Virgin Pulse) during a May 30-31 window. The exposure affected roughly 845,441 Sutter patients and included names, addresses, phone numbers, emails, dates of birth, insurance-provider details, doctor names, diagnosis/treatment codes, and clinical metrics such as weight and blood pressure; Social Security and payment-card numbers were not included. Sutter was notified on September 22, 2023 and disclosed on November 3, 2023. The data later appeared on Cl0p’s leak site and an underground marketplace (about 1.46 million database rows in December 2024). This was a supply-chain/vendor breach, not a direct compromise of Sutter systems.
Full threat analysis, exploitation vectors, and principal guidance below.
12 additional sections · verified field analysis · defensive doctrine
845K records analyzed
Sutter Health is a large not-for-profit integrated health system based in Sacramento, California, operating hospitals, clinics, and physician networks across Northern California and serving millions of patients. It maintains patient identity, clinical, insurance, and billing records across its facilities and works with third-party vendors for patient-engagement and administrative services.
Integrated health systems collect patient identity, contact, insurance, billing, appointment, and clinical records across hospitals, clinics, and administrative operations.
The patient data was exposed not through a direct attack on Sutter but via its patient-engagement vendor Welltok (Virgin Pulse) during the 2023 MOVEit zero-day campaign. Sutter disclosed the incident on November 3, 2023 and offered one year of credit monitoring; it was criticized for the roughly four-month delay. Litigation (Copans v. Sutter Health & Welltok) was consolidated into the federal In re MOVEit MDL.
Although Social Security and payment-card numbers were not in the Welltok dataset, the exposure of names, addresses, dates of birth, insurance and provider details, and diagnosis/treatment codes plus clinical metrics assembled a comprehensive medical dossier on roughly 845,000 patients. That breadth of PHI supports targeted medical identity theft, insurance fraud, and extortion, and the incident became a leading example of third-party vendor risk in healthcare.
• Medical identity fraud and insurance abuse using diagnosis, treatment, and insurance data | • Targeted extortion using clinical metrics and diagnosis codes | • Identity verification bypass using name + date of birth | • Targeted phishing and vishing referencing providers or treatment | • Doxxing and physical targeting from exposed home addresses
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A mature extortion group associated in public reporting with TA505 and FIN11-linked ecosystems. Cl0p is known for mass exploitation of managed file transfer products, including the 2023 MOVEit Transfer campaign exploiting CVE-2023-34362.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation