SAG-AFTRA Health Plan
ent_019e0a6495aecdb1791a7a65da5e5b18
Disclosures
9
State AG · HHS OCR · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
98,474
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SAG-AFTRA Health Plan
- Normalized
- sag aftra health plan— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- MTIHOR5S7P64873VW472
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- 🍁Vermont State AGas victim2025-03-14
SAG-AFTRA Health Plan notified consumers of a phishing incident compromising an employee's email account between Sept 17-18, 2024. The breach exposed names, SSNs, and health insurance information for participants and dependents. The Plan contained the incident, engaged forensic experts, notified law enforcement, and offered one year of Experian IdentityWorks.
- ⛰️New Hampshire State AGas victim2025-03-14
SAG-AFTRA Health Plan submitted a supplemental notice to the New Hampshire Attorney General regarding a cybersecurity incident. An employee's email account was compromised via phishing between September 17-18, 2024. The incident exposed personal information of 112 New Hampshire residents. The Plan contained the incident, engaged third-party experts, notified law enforcement, and offered credit monitoring services.
- 🐻California State AGas victim2025-03-14
SAG-AFTRA Health Plan notified California residents that an employee's email account was compromised via phishing between Sept 17-18, 2024. The unauthorized party accessed emails containing names, SSNs, and health insurance claim information for participants, spouses, and dependents. The incident was contained immediately. The Plan engaged third-party experts, notified law enforcement, and is offering one year of complimentary identity theft protection through Experian.
- 🦫Oregon State AGas victim2025-03-14
SAG-AFTRA Health Plan reported a data breach to the Oregon Attorney General. The breach was reported on 2025-03-14. The breach occurred during 9/17/2024 - 9/18/2024. The breach was discovered on 2/7/2025. 95,104 individuals were affected. Notice was sent on 3/14/2025.
- 🌲Washington State AGas victim2025-03-14
SAG-AFTRA Health Plan, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2024-09-18 and filed notice on 2025-03-14. 937 Washington residents were affected. 177 days elapsed between awareness and notification. 1 days to identify the breach. 0 days to contain the breach.
- CALIFORNIAHHS OCRas victim2024-12-02
SAG-AFTRA Health Plan reported to HHS on 2024-12-02 a Hacking/IT Incident affecting 98,474 individuals. Breached information located on Email. An employee was targeted by an email phishing scheme, exposing names, SSNs, and claims information. The entity implemented additional safeguards and retrained staff.
- ⛰️New Hampshire State AGas victim2024-12-02
SAG-AFTRA Health Plan notified the New Hampshire Attorney General of a security incident where an employee's email account was compromised via phishing between Sept 17-18, 2024. The breach exposed personal and health information of 38 NH residents. The Plan contained the incident, engaged third-party experts, notified law enforcement, and offered credit monitoring services.
- 🦬Montana State AGas victim2024-12-02
SAG-AFTRA Health Plan reported a data breach to the Montana Attorney General. The breach was reported on 2024-12-02. The breach occurred from 09/17/2024 to 03/18/2025. 60 Montana residents were affected.
- 🐻California State AGas victim2024-12-02
SAG-AFTRA Health Plan experienced a data breach after an employee's email account was compromised via a phishing email. Unauthorized access occurred between September 17 and 18, 2024. The incident exposed personal information including names, Social Security numbers, and potentially health insurance claims data for some plan participants. The Plan contained the incident, engaged third-party experts, notified law enforcement, and is offering one year of identity theft protection to affected individuals.