DisclosureLens
HackingHealthcareTechnologyHealthcareVulnerability ExploitData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDMediumContained

BAESMAN GROUP

bd_6f0ff7c39c7e5084 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 29, 2023

Filed

Feb 5, 2024

To disclose

36 weeks

Affected

306state residents only

Linked

6 filings

Confidence

65%
Full breach record for BAESMAN GROUP3 incidents on file

Baesman Group, Inc. notified HealthSun Health Plans members of unauthorized access to a MOVEit Transfer server on May 29, 2023. The attacker exfiltrated PII including names, addresses, DOBs, and member IDs. Baesman Group investigated and enhanced privacy policies. Notices were sent on February 5, 2024.

Incident timeline

discovery → filing · 36 weeks / 252 days

May 29, 2023

Begins

May 29, 2023

Discovered

Feb 5, 2024

Filed

vs. sector median

+24 wks slower

This filing is one of 6 about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 24d gap

Filing propagation · 6 filings · 5 states

View merged incident ↗

Pattern: first filing Feb 5 (MT), last Feb 29 (MA) — a 24-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.