US Wellness
Disclosed Mar 22, 20233 years ago15,818 affectedConfirmed
The business associate (BA), U.S. Wellness, reported that its third-party vendor was the victim of a cybersecurity attack that affected the protected health information (PHI) of 15,818 individuals. The PHI involved included names, addresses, and dates of birth. The BA notified HHS, affected individuals, the media, and provided substitute notice on its website. In response to the breach, the BA offered complimentary credit and identity protection services and implemented additional administrative, technical, and security safeguards.
What is known
| People affected | 15,818 (as reported to HHS) |
|---|---|
| Disclosed | Mar 22, 2023 |
| Happened | Jan 31, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: US Wellnessoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): US Wellness (Business Associate, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Mar 22, 2023 | |
| HHS archivetotal | Mar 22, 2023 | 15,818 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 15818 · backfill source
- 2026-09-25 · summary: empty to The business associate (BA), U.S. Wellness, reported that its third-party vendor was the victim of a cybersecurity attack that affected the protected health information (PHI) of 15,818 individuals. The PHI involved included names, addresses · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.