MalwareRansomwareCapture Stored DataData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedPIIIDENTITY_BASICMediumContained
Harvard Pilgrim Health Care
bd_c229892302105957 · schema v1 · pii pii-v1
Full breach record for Harvard Pilgrim Health Care →Harvard Pilgrim Health Care disclosed a ransomware incident discovered on April 17, 2023. Unauthorized access occurred between March 28 and April 17, 2023, resulting in data exfiltration. Personal information of members, including names and addresses, was potentially compromised. The company engaged forensic experts, notified law enforcement, and offered credit monitoring services.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_6228e5282fce1211Maine State AGfiled 2024-03-27Verified
- bd_653dd03a96a63057Delaware State AGfiled 2024-03-27Verified
- bd_dbc80eaf19d4bfa1California State AGfiled 2024-03-27Verified
- bd_e3cbbfda0c66639bVermont State AGfiled 2024-03-27Verified
Show 4 more filings ↓Show fewer ↑up to 41d gap
- bd_2cfb222c1f723d12New Hampshire State AGfiled 2024-02-15(41d gap)Verified
- bd_718a015221cd2671California State AGfiled 2024-02-15(41d gap)Verified
- bd_75a606d40f78de2eDelaware State AGfiled 2024-02-15(41d gap)Candidate
- bd_9dcb7294e442d8b9Maine State AGfiled 2024-02-15(41d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/harvard-pilgrim-health-care-20240327.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2024
- Raw hash
- c786bcb7c84586ae84c4c4a120e5a52a1255deb70bdddba6c68a32da27969317
Reporting entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Victim entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- —
- Notification sent
- Mar 27, 2024
- Affected individuals
- 9,766
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulators
Compliance
- Time to disclose
- 49 weeks(345 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.