Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICPHILowContained
Academic HealthPlans, Inc.
bd_0f41ff8620a51b5d · schema v1 · pii pii-v1
Full breach record for Academic HealthPlans, Inc. →Academic HealthPlans, Inc. notified California regulators of a phishing incident targeting employee email accounts between August 6, 2020, and October 2, 2020. The breach involved unauthorized access to Microsoft Office 365 accounts, potentially exposing customer PHI and basic identity information. No evidence of data exfiltration was found, but the company engaged Kroll to provide one year of complimentary identity monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-543878
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 13, 2021
- Raw hash
- 4c4e1b6772f5835919c8bdf70e5858a1d2c44e72e0782e65f018d783aca949e0
Reporting entity
- Name
- Academic HealthPlans, Inc.norm: academic healthplans
Victim entity
- Name
- Academic HealthPlans, Inc.norm: academic healthplans
Incident
- Discovered
- Jul 7, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.