DisclosureLens
Social EngineeringHealthcareFinancial ServicesHealthcarePhishingData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIIdentity (basic)Government IDHealth (basic)MediumContained

Tufts Health Plan

bd_a560968fa299072b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 1, 2020

Filed

Nov 27, 2020

To disclose

21 weeks

Affected

42state residents only

Linked

3 filings

Confidence

66%
Full breach record for Tufts Health Plan16 incidents on file

Tufts Health Plan notified the New Hampshire Attorney General of a data security incident involving its business associate, EyeMed Vision Care LLC. An unauthorized individual accessed an EyeMed email mailbox from June 24 to July 1, 2020, and sent phishing emails to contacts in the mailbox. The incident potentially affected 42 New Hampshire residents, exposing names, addresses, dates of birth, SSNs, and some medical information. EyeMed secured the account, engaged forensic investigators, and provided two years of credit monitoring to affected individuals.

Incident timeline

undetected · 7 days
discovery → filing · 21 weeks / 149 days

Jun 24, 2020

Begins

Jul 1, 2020

Discovered

Nov 27, 2020

Filed

vs. sector median

+10 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 2 states

View merged incident ↗
HHS OCRNov 25 · first
New Hampshire State AG+2d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.