CSIDB logo
Incident

Independent Clinics of Washington

Incident posture

Attack window
Jun 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-10 05:51

Linked entities

Victim
Independent Clinics of Washington
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2025
Discovered
Undetermined
Disclosed
Jun 2026
Resolved
Pending

Summary

A lawsuit alleges that Wellpoint Washington Inc. and Independent Clinics of Washington failed to adequately protect patient information from a cyberattack, delaying notification to subscribers for nearly a year and thereby increasing the risk of fraud. The proposed nationwide class action seeks damages for alleged negligence and calls for improved data protection measures.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In June 2025, a cyberattack targeted the systems of Independent Clinics of Washington and its affiliated insurer Wellpoint Washington Inc., resulting in the unauthorized access of patient information. The lawsuit alleges that both entities failed to adequately protect the data before the incident occurred. Following the breach, the organizations delayed notifying affected individuals for nearly a year, with disclosure reportedly occurring around mid‑2026. On June 12, 2026, a Washington resident filed a proposed nationwide class action lawsuit in response to the alleged shortcomings.

The complaint contends that the delayed notification left subscribers unaware of the breach for an extended period, thereby elevating the risk of fraud, identity theft, and financial harm. It argues that timely disclosure is essential to mitigate such potential consequences and that the lapse exacerbated the danger to those whose data was compromised. The lawsuit seeks damages for the alleged negligence of Wellpoint and Independent Clinics of Washington in safeguarding patient information. The case is presented as part of a growing concern over data security practices within the healthcare sector.

The plaintiffs request that Wellpoint be required to implement improved data protection measures to prevent future incidents. They also frame the litigation as one of many class actions emerging across industries that accuse organizations of insufficient security controls and untimely breach notifications. Wellpoint, noted in the filing as a subsidiary of Elevance Health Inc., faces potential liability for both the breach itself and its handling of the aftermath. The legal proceeding continues to move forward as the alleged class action proceeds through the courts.

Sources

Sources available to members: 1 source.

CSIDB