MalwareRansomwareCapture Stored DataData ExfiltratedData EncryptedRansom DemandedBusiness Associate (HIPAA)Customer Data InvolvedDownstream VictimsPIIPHIIDENTITY_BASICHEALTH_BASICLowActive
Point32Health
bd_9b8c10e974a8bb9c · schema v1 · pii pii-v1
Full breach record for Point32Health →Point32Health, a business associate of Health Plans, Inc., experienced a ransomware incident detected on April 17, 2023. Unauthorized access occurred between March 28 and April 17, 2023, resulting in data copying. Affected data includes PII and PHI of HPI subscribers. Point32Health engaged forensic experts, notified law enforcement, and is offering credit monitoring. Investigation was active as of the notice date.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/point32health-health-plans-20230630.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2023
- Raw hash
- 76639e779d560dce0ba4233269e38edae0587615db6fbd5164cd812166b2e08c
Reporting entity
- Name
- Point32Healthnorm: point32health
- Domain
- point32health.org
Victim entity
- Name
- Point32Healthnorm: point32health
- Domain
- point32health.org
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- May 17, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulators
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.