MalwareRansomwareCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPHIIDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNTLowContained
Harvard Pilgrim Health Care
bd_6137e2525e0f8889 · schema v1 · pii pii-v1
Full breach record for Harvard Pilgrim Health Care →Harvard Pilgrim Health Care experienced a ransomware incident. Unauthorized access occurred between March 28, 2023, and April 17, 2023. The organization discovered the incident on April 17, 2023. Data was copied and taken from systems. Affected data includes names, addresses, dates of birth, health insurance account information, and clinical information (diagnoses, treatments). This is a supplemental notice sent in January 2025. Two years of credit monitoring are offered.
California clockDiscovered Apr 17, 2023 → Notified Jan 21, 2025645d ✗ CA 60-day late22 months discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e97c70caa0c2a5f5Vermont State AGfiled 2025-01-21Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-597598
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 21, 2025
- Raw hash
- a539c272b3881cb95ba07e2be161f9f39394cc704903d2f8076390ba07f06eae
Reporting entity
- Name
- Point32Healthnorm: point32health
- Domain
- point32health.org
Victim entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- —
- Notification sent
- Jan 21, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulators
Compliance
- Time to disclose
- 22 months(645 days from discovery to filing)
- Compliance flags
- CA 60-day late · 645d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 17, 2023→ Notified: Jan 21, 2025645d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.