Wellcare of Washington, Inc., through its vendor Insightin Health, Inc., experienced a data breach that was disclosed in March 2026. The incident occurred between September 17 and September 23, 2025, when an unauthorized actor accessed Insightin Health’s network. The access was made possible by a design flaw in the GoAnywhere file-transfer tool used by the vendor. Insightin Health proactively provided notification to affected individuals and reported the incident to regulatory bodies. This was confirmed by the Washington State Attorney General's office.
The breach exposed member names, dates of birth, non-unique insurance provider identifiers, and in some cases, contract numbers and Medicare Beneficiary Identifiers (MBIs) issued by CMS. Provider information was also potentially exposed. While financial information and Social Security numbers were not involved, the breach affected at least 11,740 Washington residents and an estimated 1,641 Rhode Island residents. The total number of affected individuals nationally is not yet publicly known, as this incident has not appeared on the HHS public breach tool.
Data breaches often have a delayed notification period, and additional details may emerge over time. Affected individuals may receive direct notification from Wellcare of Washington or Insightin Health.