Skip to content

US Wellness

Disclosed Mar 22, 20233 years ago15,818 affectedConfirmed

Official notice

The business associate (BA), U.S. Wellness, reported that its third-party vendor was the victim of a cybersecurity attack that affected the protected health information (PHI) of 15,818 individuals. The PHI involved included names, addresses, and dates of birth. The BA notified HHS, affected individuals, the media, and provided substitute notice on its website. In response to the breach, the BA offered complimentary credit and identity protection services and implemented additional administrative, technical, and security safeguards.

What is known

People affected15,818 (as reported to HHS)
DisclosedMar 22, 2023
HappenedJan 31, 2023
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: US Wellnessoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): US Wellness (Business Associate, MD)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAMar 22, 2023
HHS archivetotalMar 22, 202315,818
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 15818 · backfill source
  • 2026-09-25 · summary: empty to The business associate (BA), U.S. Wellness, reported that its third-party vendor was the victim of a cybersecurity attack that affected the protected health information (PHI) of 15,818 individuals. The PHI involved included names, addresses · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about US Wellness

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.