Social EngineeringPhishingTargetedIDENTITY_GOVERNMENTIDENTITY_BASICPHIMediumContained
Health Management Systems of America
bd_f8e9a72c245025ea · schema v1 · pii pii-v1
Full breach record for Health Management Systems of America →Health Management Systems of America (HMSA) reported a data breach to the Vermont Attorney General involving one Vermont resident. On December 9, 2024, HMSA detected unauthorized access to a single email account caused by a spear phishing campaign. The attacker accessed protected health information and Social Security numbers. HMSA secured the account, reset passwords, and engaged forensic investigators. Notification was sent to the affected individual in February 2026, offering 12 months of credit monitoring via Kroll.
Vermont clock✗ VT AG >45 bday16 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-03-22-health-management-systems-america-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2026
- Raw hash
- d2fe8a4a31cb13f6f701c51af0a972620eb4f2620cb2fa4aa539e6b30c117c2e
Reporting entity
- Name
- Kennedys CMK LLPnorm: kennedys cmk
Victim entity
- Name
- Health Management Systems of Americanorm: health management systems of america
- Domain
- hmsanet.com
Incident
- Discovered
- Dec 9, 2024
- Materiality determined
- —
- Notification sent
- Dec 3, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Department of Health and Human Services with the Office of Civil Rights
- Initial access
- phishing_link
Compliance
- Time to disclose
- 16 months(468 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.