MalwareRansomwareData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Harvard Pilgrim Health Care
bd_43df96fb4369f148 · schema v1 · pii pii-v1
Full breach record for Harvard Pilgrim Health Care →Harvard Pilgrim Health Care experienced a ransomware incident discovered on April 17, 2023. Unauthorized access occurred between March 28 and April 17, 2023, during which data was copied and exfiltrated. Affected data includes PHI, PII, SSNs, and health insurance account information. Systems were taken offline to contain the threat. Third-party experts were engaged. Credit monitoring offered.
California clockDiscovered Apr 17, 2023 → Notified Jul 20, 202394d ✗ CA 60-day late13 weeks discovery → filing
This filing is one of 17 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_4f27d49d5d52c9f4New Hampshire State AGfiled 2023-07-20Verified
- bd_5a3a5e82cf85cf22Vermont State AGfiled 2023-07-20Verified
- bd_666d77ef4e010847Delaware State AGfiled 2023-07-20Verified
- bd_d027e78d7ded6e28Maine State AGfiled 2023-07-20Verified
Show 6 more filings ↓Show fewer ↑up to 36d gap
- bd_e57af67926649807Delaware State AGfiled 2023-08-15(26d gap)Verified
- bd_826a042bdbb8ed5eNew Hampshire State AGfiled 2023-08-24(35d gap)Verified
- bd_2566648ff734018eVermont State AGfiled 2023-06-15(35d gap)Verified
- bd_73394de7a4caf43fCalifornia State AGfiled 2023-08-25(36d gap)Verified
- bd_7fa77c84f4ff9123Maine State AGfiled 2023-08-25(36d gap)Verified
- bd_a5d7c5d7c31e5762Vermont State AGfiled 2023-08-25(36d gap)Verified
Showing first 10 of 16 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570608
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 20, 2023
- Raw hash
- 99acf522108f7ba661232cd382f9b37fd39265ad49cb23589251e03f7491747d
Reporting entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Victim entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- —
- Notification sent
- Jul 20, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulators
Compliance
- Time to disclose
- 13 weeks(94 days from discovery to filing)
- Compliance flags
- CA 60-day late · 94d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 17, 2023→ Notified: Jul 20, 202394d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.