Aya Healthcare
bd_1e9f96661e12cc26 · schema v1 · pii pii-v1
Full breach record for Aya Healthcare →Aya Healthcare, Inc. notified individuals of a data security incident where unauthorized third parties used stolen credentials (obtained from unrelated sources) to access user accounts. The breach, discovered on January 12, 2025, involved an automated bot viewing limited personal information including names, SSNs, and license numbers. Aya engaged cybersecurity experts, reset passwords, and offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 12, 2025
Discovered
Feb 27, 2025
Filed
vs. sector median
12 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Indiana State AGbd_004fdddbe99699342025-02-27Verified
- Maryland State AGbd_1feaf1979c4f40912025-02-27Verified
- Massachusetts State AGbd_4508cc0d2cafce792025-02-27Verified
- Maine State AGbd_514b32eabd91432c2025-02-27Verified
Show 2 more filings ↓Show fewer ↑
- Nebraska State AGbd_9f07b90a54fb92ef2025-02-27Verified
- Vermont State AGbd_a9f3734972f435022025-02-27Verified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.