MalwareRansomwareData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIDENTITY_BASICHEALTH_BASICHighContained
OneTouchPoint, Inc.
bd_e698df42a44ea43a · schema v1 · pii pii-v1
Full breach record for OneTouchPoint, Inc. →Matrix Medical Network reported a cybersecurity incident involving its vendor, OneTouchPoint, Inc. (OTP). OTP discovered encrypted files (ransomware) on its systems on April 28, 2022, with unauthorized access beginning April 27, 2022. The incident affected approximately 1,073,316 individuals nationwide, including 7 Delaware residents. Data potentially accessed included names, member IDs, and health assessment information. OTP notified law enforcement, engaged forensic specialists, and sent notices to affected individuals starting July 27, 2022.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_3476e8e6d17935bcMontana State AGfiled 2022-07-27Verified
- bd_81a1eff32dae4681Oregon State AGfiled 2022-07-27Verified
- bd_860d2c865585bc00Maine State AGfiled 2022-07-27Verified
- bd_9615d33ec85275eeHHS OCRfiled 2022-07-27Verified
Show 4 more filings ↓Show fewer ↑up to 30d gap
- bd_9950fe17fad3a387Washington State AGfiled 2022-07-27Verified
- bd_3717777616d4b9c4Montana State AGfiled 2022-08-01(5d gap)Verified
- bd_926be1d673f541faCalifornia State AGfiled 2022-08-12(16d gap)Verified
- bd_93b9d15ec0e6d38fMaine State AGfiled 2022-08-26(30d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/09/Exh-A-Description-of-Data-Event.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2022
- Raw hash
- 9036282d0e31cf716aafc06e47d5f9d8a8f4c4971e0535565964c0fdb95c49f8
Reporting entity
- Name
- Matrix Medical Networknorm: matrix medical network
Victim entity
- Name
- OneTouchPoint, Inc.norm: onetouchpoint
- Domain
- onetouchpoint.com
Incident
- Discovered
- Apr 28, 2022
- Materiality determined
- —
- Notification sent
- Jul 27, 2022
- Affected individuals
- 1,073,316
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1486 Data Encrypted for Impact
- Threat actor
- External
- Regulator citations
- Notified Delaware Attorney General's office
- Third party
- via OneTouchPoint, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.