CSIDB logo
Incident

Wellpoint Washington Inc.

Incident posture

Attack window
Jun 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-10 05:52

Linked entities

Victim
Wellpoint Washington Inc.
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2025
Discovered
Undetermined
Disclosed
Jun 2026
Resolved
Pending

Summary

A Washington resident filed a proposed nationwide class action accusing Wellpoint Washington Inc. and Independent Clinics of Washington of failing to protect patient information from a cyberattack and of delaying notification to subscribers for nearly a year. The lawsuit claims that the delayed notice increased the risk of fraud, including identity theft and financial fraud, by leaving affected individuals unaware of the breach. It highlights broader concerns about data security in the healthcare sector and seeks damages for alleged negligence while urging improved data protection measures.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In June 2025, Wellpoint Washington Inc. and Independent Clinics of Washington experienced a cyberattack that compromised patient information. The lawsuit alleges that the insurer failed to adequately protect the patient data from this attack. Wellpoint is described as a subsidiary of Elevance Health Inc. Independent Clinics of Washington is identified as a health services provider partnered with Wellpoint in the incident.

The plaintiff claims that Wellpoint did not notify affected subscribers until nearly a year after the breach occurred. According to the lawsuit, the delay in notification left individuals unaware of the compromise for an extended period. The plaintiff argues that this delayed disclosure heightened the risk of fraud, identity theft, and financial fraud for the affected individuals. The lawsuit was filed on June 12, 2026, as a proposed nationwide class action in the Washington state court system. The complaint seeks damages for the alleged negligence and requests that Wellpoint improve its data protection measures. The case is part of a broader trend of class actions targeting organizations that fail to secure sensitive data or disclose breaches promptly.

The article notes that the lawsuit highlights growing concerns about data security in the healthcare sector. It states that sensitive patient information is often targeted by cybercriminals. Wellpoint, as a subsidiary of Elevance Health Inc., faces potential liability for both the breach itself and its handling of the aftermath. The plaintiff’s requested relief includes monetary compensation and changes to Wellpoint’s data protection practices. No further technical details about the attack vector, detection, or containment are provided in the source material. The narrative is limited to the allegations and claims presented in the lawsuit filing.

Sources

Sources available to members: 1 source.

CSIDB