MalwareRansomwareData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Harvard Pilgrim Health Care
bd_dbc80eaf19d4bfa1 · schema v1 · pii pii-v1
Full breach record for Harvard Pilgrim Health Care →Harvard Pilgrim Health Care disclosed a ransomware incident where an unauthorized party accessed systems from March 28 to April 17, 2023. The organization discovered the incident on April 17, 2023, and took systems offline to contain the threat. Investigation confirmed data was copied and taken. This supplemental notice informs affected individuals, including approximately 9,766 Rhode Island residents, about the potential exposure of personal and health information. Credit monitoring services are being offered.
California clockDiscovered Apr 17, 2023 → Notified Mar 27, 2024345d ✗ CA 60-day late49 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_6228e5282fce1211Maine State AGfiled 2024-03-27Verified
- bd_653dd03a96a63057Delaware State AGfiled 2024-03-27Verified
- bd_c229892302105957New Hampshire State AGfiled 2024-03-27Verified
- bd_e3cbbfda0c66639bVermont State AGfiled 2024-03-27Verified
Show 4 more filings ↓Show fewer ↑up to 41d gap
- bd_2cfb222c1f723d12New Hampshire State AGfiled 2024-02-15(41d gap)Verified
- bd_718a015221cd2671California State AGfiled 2024-02-15(41d gap)Verified
- bd_75a606d40f78de2eDelaware State AGfiled 2024-02-15(41d gap)Candidate
- bd_9dcb7294e442d8b9Maine State AGfiled 2024-02-15(41d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-583130
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2024
- Raw hash
- 4808dc25246894ae68e3f98c1fb83caeb37cec84da4e8353f98d425443522b71
Reporting entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Victim entity
- Name
- Harvard Pilgrim Health Carenorm: harvard pilgrim health care
- Domain
- point32health.org
Incident
- Discovered
- Apr 17, 2023
- Materiality determined
- —
- Notification sent
- Mar 27, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulators
Compliance
- Time to disclose
- 49 weeks(345 days from discovery to filing)
- Compliance flags
- CA 60-day late · 345d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 17, 2023→ Notified: Mar 27, 2024345d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.