MalwareRansomwareCapture Stored DataData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
Harvard Pilgrim Health Care
bd_2cfb222c1f723d12 · schema v1 · pii pii-v1
Full breach record for Harvard Pilgrim Health Care →Harvard Pilgrim Health Care reported a ransomware incident discovered on April 17, 2023. Unauthorized access led to data copying. The company took systems offline, engaged forensic experts, and notified law enforcement. Personal information, potentially including SSNs, was involved. Notices were sent on Feb 15, 2024, offering credit monitoring. At least 1,347 Rhode Island residents were impacted.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_718a015221cd2671California State AGfiled 2024-02-15Verified
- bd_75a606d40f78de2eDelaware State AGfiled 2024-02-15Candidate
- bd_9dcb7294e442d8b9Maine State AGfiled 2024-02-15Verified
- bd_6228e5282fce1211Maine State AGfiled 2024-03-27(41d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 41d gap
- bd_653dd03a96a63057Delaware State AGfiled 2024-03-27(41d gap)Verified
- bd_c229892302105957New Hampshire State AGfiled 2024-03-27(41d gap)Verified
- bd_dbc80eaf19d4bfa1California State AGfiled 2024-03-27(41d gap)Verified
- bd_e3cbbfda0c66639bVermont State AGfiled 2024-03-27(41d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/harvard-pilgrim-health-care-20240215.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 15, 2024
- Raw hash
- ab94dc8d31b3780e9e8acb24606d308b961fa15aac68b008d3a4b0d0d6b7e683
Reporting entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Victim entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- Jan 4, 2024
- Notification sent
- Feb 15, 2024
- Affected individuals
- 1,347
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulators
Compliance
- Time to disclose
- 43 weeks(304 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.