Harvard Pilgrim Health Care
bd_653dd03a96a63057 · schema v1 · pii pii-v1
Full breach record for Harvard Pilgrim Health Care →Harvard Pilgrim Health Care, a subsidiary of Point32Health, disclosed a ransomware incident discovered on April 17, 2023. The attack impacted systems servicing members, accounts, brokers, and providers. Data was copied between March 28 and April 17, 2023, potentially exposing personal information including names, Social Security numbers, dates of birth, and driver's license numbers. Approximately 9,766 Rhode Island residents were specifically identified as impacted. The company took systems offline, notified law enforcement, engaged forensic experts, and offered two years of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_6228e5282fce1211Maine State AGfiled 2024-03-27Verified
- bd_c229892302105957New Hampshire State AGfiled 2024-03-27Verified
- bd_dbc80eaf19d4bfa1California State AGfiled 2024-03-27Verified
- bd_e3cbbfda0c66639bVermont State AGfiled 2024-03-27Verified
Show 4 more filings ↓Show fewer ↑up to 41d gap
- bd_2cfb222c1f723d12New Hampshire State AGfiled 2024-02-15(41d gap)Verified
- bd_718a015221cd2671California State AGfiled 2024-02-15(41d gap)Verified
- bd_75a606d40f78de2eDelaware State AGfiled 2024-02-15(41d gap)Candidate
- bd_9dcb7294e442d8b9Maine State AGfiled 2024-02-15(41d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/04/Harvard-Pilgrim.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2024
- Raw hash
- 6e6e709d9247ff41ab2d18ee24427d774ae6a17dada74c184a8697d339fac092
Reporting entity
- Name
- Point32Healthnorm: point32health
- Domain
- point32health.org
Victim entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 9,766
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulators
Compliance
- Time to disclose
- 49 weeks(345 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.