WVU Medecine Data Breach
WVU Medicine Academic Health System Breach (2023): 2.9 Million Patient Records Including Medical Diagnoses & SSN
Academic health system affiliated with West Virginia University.
Risk Interpretation
Severe risk. The combination of SSNs, home addresses, account balance data, and medical diagnosis supports identity theft, medical fraud, insurance abuse, and highly targeted scams exploiting health status or unpaid balances.
Impact & Downstream Threats
In 2023 WVU Medicine was affected by breaches through two third-party vendors. One involved unauthorized access to the ECHO Provider Services portal, compromising patient information including names and insurance details. A separate vendor incident resulted in more extensive exposure including account balances, email addresses, home addresses, phone numbers, Social Security numbers, and medical diagnoses across approximately 2.9 million records. WVU Medicine notified affected patients and report
- Identity theft and synthetic identity construction using government-issued IDs
- SIM swap attacks where phone numbers are present
- Targeted phishing campaigns using exposed email addresses
- Doxxing risk from physical address exposure
- Medical identity fraud or insurance abuse using health data
Threat Vectors
Breach Intelligence
Executive Summary
WVU Medicine, the academic health system affiliated with West Virginia University, suffered data breaches in 2023 through two third-party vendors. One incident involved unauthorized access to the ECHO Provider Services portal, exposing patient names and insurance details. A separate vendor breach was far broader in scope, ultimately compromising approximately 2.9 million records. The more extensive breach exposed a serious combination of personal, financial, and medical information: names, home addresses, email addresses, phone numbers, Social Security numbers, account balances, and medical diagnoses. This combination is particularly dangerous. Social Security numbers enable identity theft and fraudulent credit activity, while medical diagnoses paired with account balances can be used to craft highly targeted scams that exploit a patient's health condition or outstanding bills. WVU Medicine notified affected patients and reported both incidents to regulators as required under HIPAA, the federal law governing the privacy of patient health information. No major settlement or public enforcement action specific to these breaches has been documented. Affected individuals face elevated long-term risk of identity theft, medical fraud, and insurance abuse, and should closely monitor their credit reports, explanation-of-benefits statements, and any financial accounts for suspicious activity.
About WVU Medecine
WVU Medicine is the academic health system affiliated with West Virginia University, operating hospitals, specialty clinics, and outpatient facilities across West Virginia and the surrounding region. Its flagship facility is J.W. Ruby Memorial Hospital in Morgantown. The system serves as the primary tertiary care provider for much of rural West Virginia and provides clinical training for WVU's health sciences programs.
Why They Hold Your Data
Healthcare systems and hospital networks aggregate patient identity, contact, billing, insurance, and diagnosis data across clinical and vendor-connected systems.
Recent Developments
WVU Medicine has continued expanding its clinical and community health services across West Virginia. The system has invested in rural health access and telehealth infrastructure to serve a dispersed patient population. No major organizational changes beyond the breach context have been prominently reported.
Data Points Exposed
Exposure Categories
Canonical Fields
account_balance, email_address, full_name, medical_diagnosis, phone_number, physical_address:home, ssn
Dark Web Verification
- Dataset containing ~2.9M records identified in breach intelligence sources
- Data indexed and searchable across breach notification platforms
- Source: wvumedicine.org-2024
Recommended Actions
⚠️ Do not assume this is low sensitivity.
Protect Yourself
Check If You’re Affected
Enter your email to check if your data appears in this breach.
Get Free Breach Alerts
Be the first to know when new breaches are disclosed.
High-Risk? Get an Exposure Audit
Full-spectrum exposure audits for executives and public figures.
ObscureIQ Advisory
We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.
- A public-facing individual
- A high-profile executive
- A customer of WVU Medecine
- Or concerned about credential reuse
Powered by the ObscureIQ Breach Intelligence Database
© 2026 ObscureIQ · All Rights Reserved · Data Licensing
Latest from ObscureIQ
What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.
Sextortion Spam
