DisclosureLens
Social EngineeringHealthcareIdentity (basic)Government IDFinancial accountHealth (basic)MediumContained

Huggins Insurance Se

bd_61ee7fd1fd264154 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 16, 2019

Filed

May 24, 2019

To disclose

18 weeks

Affected

Not disclosed

Linked

4 filings

Confidence

67%
Full breach record for Huggins Insurance Se

Huggins Insurance, an Oregon-based insurance broker, notified the New Hampshire Attorney General of a data security incident involving two NH residents. On January 16, 2019, Huggins discovered unauthorized access to employee email accounts via phishing. The breach exposed names, SSNs, driver's license numbers, health insurance policy numbers, credit/debit card numbers, financial account numbers, and medical information. Huggins engaged forensic investigators, notified the FBI and credit bureaus, and offered one year of complimentary credit monitoring to affected individuals.

Incident timeline

discovery → filing · 18 weeks / 128 days

Jan 16, 2019

Discovered

May 24, 2019

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 3 states

View merged incident ↗
HHS OCRMay 24 · first
Montana State AGMay 24 · first
Oregon State AGMay 24 · first
New Hampshire State AGMay 24 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.