HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Health Plan Intermediaries Holdings
bd_41f71974fa13689e · schema v1 · pii pii-v1
Full breach record for Health Plan Intermediaries Holdings →Health Plan Intermediaries Holdings (Benefytt) notified individuals of a data breach involving their personal information. The incident occurred on Orrick, Herrington & Sutcliffe, LLP's systems, which served as legal counsel to MultiPlan, Inc., a vendor of Benefytt. On March 10, 2023, an unauthorized third party gained remote access to Orrick's network. Orrick detected the access on March 13, 2023. The breach affected plan participant information, including potential PHI and PII. Benefytt is offering identity monitoring services through Equifax.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582906
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2024
- Raw hash
- a089868c39ca78094f6395dab4cb6d9c9701082ab9bf9425151c0374a26b0843
Reporting entity
- Name
- Health Plan Intermediaries Holdingsnorm: health plan intermediaries
Victim entity
- Name
- Health Plan Intermediaries Holdingsnorm: health plan intermediaries
Incident
- Discovered
- Mar 13, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Orrick, Herrington & Sutcliffe, LLP
Compliance
- Time to disclose
- 13 months(375 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.