Healthfirst
bd_30a785c0bb884175 · schema v1 · pii pii-v1
Full breach record for Healthfirst →4 incidents on fileHealthfirst, a New York-based Health Plan, reported to HHS OCR on 2024-03-13 a ransomware incident affecting the PHI of 6,836 individuals. Breached information was located on a Network Server. PHI exposed included names, addresses, and dates of birth. The CE notified HHS, affected individuals, and the media, posted substitute notice on its website, offered free credit monitoring, and implemented additional safeguards and staff training.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Mar 13, 2024
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.