Skip to content

Wolverine Solutions Group

Disclosed Dec 28, 20187 years ago1,024,731 affectedConfirmed

Official notice

The business associate (BA), Wolverine Solutions Group, reported that it was the victim of a ransomware attack affecting the protected health information (PHI) of 1,024,731 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license numbers, Social Security numbers, health insurance information, claims information, diagnoses, lab results, and medications. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA offered complimentary credit monitoring services to affected individuals, and implemented additional administrative, technical and security safeguards.

What is known

People affected1,024,731 (as reported to HHS)
DisclosedDec 28, 2018
HappenedSep 23, 2018
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
California AGresidents of CADec 28, 2018
HHS archivetotalDec 28, 20181,024,731
California AGresidents of CAMar 25, 2019
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 1024731 · backfill source
  • 2026-09-25 · summary: empty to The business associate (BA), Wolverine Solutions Group, reported that it was the victim of a ransomware attack affecting the protected health information (PHI) of 1,024,731 individuals. The PHI involved included names, addresses, dates of b · backfill source
  • 2026-09-25 · disclosed: 2019-03-25 to 2018-12-28 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Wolverine Solutions Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.