DataPath, Inc.
bd_588ce489c8159230 · schema v1 · pii pii-v1
Full breach record for DataPath, Inc. →DataPath, Inc., a third-party administrative services provider for Health Savings Accounts (HSAs), discovered unauthorized access to its computer network on December 15, 2021. An investigation determined that an unauthorized party gained access to certain systems on or before that date. The incident potentially impacted the name and address of individuals whose HSA accounts were administered by DataPath. DataPath engaged third-party cybersecurity specialists, notified federal law enforcement, and is offering credit monitoring and identity restoration services through Experian to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 15, 2021
Begins
Dec 15, 2021
Discovered
Dec 1, 2022
Filed
vs. sector median
+42 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Montana State AGbd_a797d4faa87ed95e2022-12-01Candidate
- Indiana State AGbd_a8dd62c83775a7662022-12-01Verified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.