Harvard Pilgrim Health Care
bd_7d6e82e2351b46c6 · schema v1 · pii pii-v1
Full breach record for Harvard Pilgrim Health Care →Harvard Pilgrim Health Care experienced a ransomware incident discovered on April 17, 2023. Unauthorized access occurred between March 28 and April 17, 2023, during which data was copied and taken from systems. The incident involved personal information and protected health information (PHI) of members, accounts, brokers, and providers. Systems were taken offline to contain the threat. Third-party forensic experts were engaged. Additional cybersecurity safeguards were implemented. Affected individuals are offered two years of complimentary credit monitoring and identity protection services.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3d033309f7ace5ebDelaware State AGfiled 2024-10-03Verified
- bd_59b7d4f12c5ff2b6Maine State AGfiled 2024-10-03Candidate
- bd_9b1c4d63a64d8aabNew Hampshire State AGfiled 2024-10-03Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-592846
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 3, 2024
- Raw hash
- 021cc2651ef1cc92971de1f392a07b7f3546c3c4e2189a08acbdb57943003789
Reporting entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Victim entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- —
- Notification sent
- Oct 3, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIPIIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulators
Compliance
- Time to disclose
- 18 months(535 days from discovery to filing)
- Compliance flags
- CA 60-day late · 535d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 17, 2023→ Notified: Oct 3, 2024535d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.