HackingCapture Stored DataData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICHEALTH_BASICLowContained
Benefits Administration Services, Inc.
bd_1a00006def5499b7 · schema v1 · pii pii-v1
Full breach record for Benefits Administration Services, Inc. →Benefit Administrative Systems, LLC (BAS), administrator of the Connected Care Health Plan, experienced unauthorized access to its network. On November 1, 2022, BAS confirmed exfiltration of a file containing member names, email addresses, health insurance member numbers, and health insurance group numbers. No SSNs, financial data, or medical/claim information were involved. BAS engaged outside cybersecurity experts and worked with federal law enforcement. Affected individuals were offered 12-month Experian IdentityWorks membership.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_d6281484aed79befHHS OCRfiled 2023-01-27Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-562401
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 27, 2023
- Raw hash
- f4ecae2ddb1fb02f57afd86fb268f67a377f654786d96fb7bd48dac25215358a
Reporting entity
- Name
- Benefits Administration Services, Inc.norm: benefits administration
- Domain
- bashealth.com
Victim entity
- Name
- Benefits Administration Services, Inc.norm: benefits administration
- Domain
- bashealth.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jan 30, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.