
Westat, Inc., a renowned research and communications entity headquartered in Rockville, Maryland, disclosed two data breach incidents to the U.S. Department of Health and Human Services Office for Civil Rights. The breach, stemming from a vulnerability within the MOVEit software, resulted in unauthorized access to sensitive consumer information, as outlined in reports submitted by Westat.
The breach, unveiled during Westat’s internal scrutiny, occurred between May 28, 2023, and May 29, 2023, when an unauthorized entity accessed and potentially extracted files containing confidential consumer data. The accessed information includes individuals’ names, Social Security numbers, and protected health data, impacting an estimated 70,000 individuals based on the company’s filings with HHS-OCR on October 13, 2023, and November 3, 2023.
Upon discovering the breach, Westat initiated a comprehensive investigation, partnering with cybersecurity experts to delve deeper into the incident. Subsequently, the company embarked on notifying all affected individuals through data breach notification letters, aiming to provide details about the compromised data.
Despite ongoing investigations into the breach, the precise nature and extent of the compromised data remain under scrutiny, pending further revelations anticipated soon. Individuals impacted by the breach are urged to stay informed and vigilant, considering potential risks associated with the exposed sensitive information, such as identity theft or fraud.
Westat, a significant player in research and statistical surveys, offers diverse services, including program assessments, clinical trial management, epidemiological studies, and communication strategies. It has a workforce exceeding 1,700 individuals and an annual revenue of approximately $367 million.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543