Skip to content

WellDyneRX

Disclosed May 6, 20224 years ago49,964 affectedConfirmed

Official notice

The covered entity (CE), WellDyneRX, reported that an employee was the subject of a phishing attack that affected the protected health information (PHI) of 49,964 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, and clinical and health insurance information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Workforce members were retrained to better protect its PHI.

What is known

People affected49,964 (as reported to HHS)
DisclosedMay 6, 2022
DiscoveredDec 2, 2021
HappenedOct 30, 2021
AttackPhishing
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: WellDyneRXoag.ca.gov · Official notice
California Attorney General breach notice: WellDyneRxoag.ca.gov · Official notice
Washington Attorney General breach notice: WellDyneRxatg.wa.gov · Official notice
Indiana Attorney General 2022 data breach report: WellDyneRxin.gov · Official notice
HHS OCR breach report (archive, resolved): WellDyneRx (Business Associate, FL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMay 6, 20225,122
Indiana AGresidents of INMay 24, 2022336
California AGresidents of CAJul 1, 2022
HHS archivetotalJul 1, 202249,964
California AGresidents of CASep 15, 2022
Washington AGresidents of WASep 15, 2022585

Other breaches at WellDyneRX

BreachAffected
Disclosed Aug 25, 2026Aug 254 weeks agoHacking500
History of this record
  • 2026-09-25 · disclosed: 2022-05-24 to 2022-05-06 · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 974 to 49964 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), WellDyneRX, reported that an employee was the subject of a phishing attack that affected the protected health information (PHI) of 49,964 individuals. The PHI involved included names, addresses, dates of birth, driv · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 974 · backfill source
  • 2026-09-25 · disclosed: 2022-07-01 to 2022-05-24 · backfill source
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to phishing · backfill source
  • 2026-09-25 · discovered: empty to 2021-12-02 · backfill source
  • 2026-09-25 · disclosed: 2022-09-15 to 2022-07-01 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about WellDyneRX

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.