OneTouchPoint, Inc.
bd_926be1d673f541fa · schema v1 · pii pii-v1
Full breach record for OneTouchPoint, Inc. →OneTouchPoint, Inc. (OTP), a printing and mailing services vendor for health insurers and providers, experienced a security breach involving unauthorized access to its servers beginning April 27, 2022. OTP discovered encrypted files on April 28, 2022, indicating a ransomware attack. While specific file contents were undetermined, impacted systems contained personal information (PII). OTP engaged third-party forensic specialists, notified law enforcement, and sent breach notifications to affected individuals starting June 3, 2022. No evidence of misuse was found, and business customers' systems were not impacted.
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_3717777616d4b9c4Montana State AGfiled 2022-08-01(11d gap)Verified
- bd_93b9d15ec0e6d38fMaine State AGfiled 2022-08-26(14d gap)Verified
- bd_3476e8e6d17935bcMontana State AGfiled 2022-07-27(16d gap)Verified
- bd_81a1eff32dae4681Oregon State AGfiled 2022-07-27(16d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 16d gap
- bd_860d2c865585bc00Maine State AGfiled 2022-07-27(16d gap)Verified
- bd_9615d33ec85275eeHHS OCRfiled 2022-07-27(16d gap)Verified
- bd_9950fe17fad3a387Washington State AGfiled 2022-07-27(16d gap)Verified
- bd_e698df42a44ea43aDelaware State AGfiled 2022-07-27(16d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556196
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 12, 2022
- Raw hash
- 8aa6391286d03e44b6d80d804c29273c5b32fa15408e60e16a560406d3d62bf3
Reporting entity
- Name
- OneTouchPoint, Inc.norm: onetouchpoint
- Domain
- onetouchpoint.com
Victim entity
- Name
- OneTouchPoint, Inc.norm: onetouchpoint
- Domain
- onetouchpoint.com
Incident
- Discovered
- Apr 28, 2022
- Materiality determined
- —
- Notification sent
- Jun 3, 2022
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- External
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 36d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 28, 2022→ Notified: Jun 3, 202236d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.