Employee Benefit Management Services, LLC
ent_019e0d23ad2934fc71e6abb6dc9a239c
Disclosures
7
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
29,119
nationwide · HHS OCR KS
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Employee Benefit Management Services, LLC
- Normalized
- employee benefit management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300USL2RA3LR7N908
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- New Hampshire State AGas victim2024-07-02
Benefit Management, LLC (BML), a provider of administrative services to healthcare entities, notified New Hampshire residents of a data incident. On or about April 17, 2023, BML detected suspicious activity in an email account, determined unauthorized access occurred between April 14-17, 2023. The incident involved phishing leading to credential compromise. BML engaged forensic specialists, notified law enforcement and regulators, and offered 12 months of credit monitoring.
- KANSASHHS OCRas victim2024-06-12
Benefit Management LLC, a Business Associate based in Kansas, reported to HHS on 2024-06-12 a Hacking/IT Incident (email phishing attack) affecting 8,777 individuals. An employee was the subject of a phishing attack compromising PHI stored in Email systems. Exposed data included names, addresses, dates of birth, driver's license numbers, Social Security numbers, claims and financial information, diagnoses, lab results, medications, and other treatment information. The BA notified HHS, affected individuals, and the media, and provided credit monitoring services and implemented additional safeguards.
- Vermont State AGas victim2024-03-29
Benefit Management Corporation notified consumers of a data breach where an unauthorized individual accessed the network between Sept 8-11, 2023. The incident involved access to names and personal data. BMC enhanced security protocols and provided one year of free identity monitoring via Kroll.
- New Hampshire State AGas victim2024-03-29
Benefit Management Corporation notified the New Hampshire Attorney General of a security incident where an unauthorized third party accessed its network between September 8 and 11, 2023. The breach involved personal information of NH residents. Notifications began November 14, 2023, with supplemental notices in February 2024. The company offered credit monitoring and fraud consultation via Kroll.
- Montana State AGas victim2023-06-06
Benefit Management, LLC notified Montana residents of a data breach involving unauthorized access to email accounts from March 14 to April 2, 2022. The incident was discovered on April 1, 2022, following suspicious activity. Personal information, including names, was accessed. The company engaged forensic specialists, notified law enforcement and regulators, and offered credit monitoring services.
- KANSASHHS OCRas victim2023-01-27
Benefit Management, LLC reported to HHS on 2023-01-27 a Hacking/IT Incident affecting 29,119 individuals. Breached information located on Email. Employees were subjects of an email phishing scheme compromising PHI including names, addresses, DOB, driver's licenses, SSNs, claims, financial info, diagnoses, lab results, and medications.
- New Hampshire State AGas reporting2019-02-28
McAvinney Employee Benefit Services LLC notified the NH AG of a data incident on Feb 28, 2019. Unauthorized access occurred around Feb 6, 2019, via stolen employee credentials to a third-party cloud backup site. One NH resident's PII (name, SSN, email, address) was potentially accessed. Notices mailed Feb 27, 2019.