MalwareRansomwareData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Harvard Pilgrim Health Care
bd_718a015221cd2671 · schema v1 · pii pii-v1
Full breach record for Harvard Pilgrim Health Care →Harvard Pilgrim Health Care disclosed a ransomware incident where an unauthorized party accessed systems from March 28 to April 17, 2023. The organization discovered the incident on April 17, 2023, and took systems offline. Investigation confirmed data was copied and taken. This supplemental notice informs affected individuals, including California and Rhode Island residents, that their personal and health information may have been involved. Credit monitoring services are being provided.
California clockDiscovered Apr 17, 2023 → Notified Feb 15, 2024304d ✗ CA 60-day late43 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_2cfb222c1f723d12New Hampshire State AGfiled 2024-02-15Verified
- bd_75a606d40f78de2eDelaware State AGfiled 2024-02-15Candidate
- bd_9dcb7294e442d8b9Maine State AGfiled 2024-02-15Verified
- bd_6228e5282fce1211Maine State AGfiled 2024-03-27(41d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 41d gap
- bd_653dd03a96a63057Delaware State AGfiled 2024-03-27(41d gap)Verified
- bd_c229892302105957New Hampshire State AGfiled 2024-03-27(41d gap)Verified
- bd_dbc80eaf19d4bfa1California State AGfiled 2024-03-27(41d gap)Verified
- bd_e3cbbfda0c66639bVermont State AGfiled 2024-03-27(41d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-581092
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 15, 2024
- Raw hash
- 829935e7e850b0432c05dcb75da1c5a0a8956786d8310f2baa213bd37d88342d
Reporting entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Victim entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- —
- Notification sent
- Feb 15, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulators
Compliance
- Time to disclose
- 43 weeks(304 days from discovery to filing)
- Compliance flags
- CA 60-day late · 304d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 17, 2023→ Notified: Feb 15, 2024304d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.