BAESMAN GROUP
bd_dd0e6d5ccd2249d0 · schema v1 · pii pii-v1
Full breach record for BAESMAN GROUP →3 incidents on fileBaesman Group, Inc. notified the California AG of a data breach involving unauthorized access to a third-party MOVEit Transfer server on May 29, 2023. An unknown actor exploited security issues in Progress Software's MOVEit tool to access and exfiltrate data. Affected individuals' names and health-related data were involved. Baesman Group is a service provider to health plans administered by Elevance Health entities. The company launched an investigation, reviewed impacted data, and is enhancing privacy policies.
J jump to incidentP pin to compareR raw source
Incident timeline
May 29, 2023
Begins
Feb 12, 2024
Filed
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Montana State AGbd_6f0ff7c39c7e50842024-02-05 · +7dCandidate
- Oregon State AGbd_47adc8a39b47e7952024-02-29 · +17dVerified
- California State AGbd_808fe2ae0525500f2024-02-29 · +17dVerified
- Washington State AGbd_be036d2299c0c6a22024-02-29 · +17dVerified
Show 1 more filing ↓Show fewer ↑up to 17d gap
- Massachusetts State AGbd_f040b7be18297b812024-02-29 · +17dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Feb 5 (MT), last Feb 29 (MA) — a 24-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.