Service & Access Management, Inc.
ent_072c2010c332aeab
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,450
as filed · HHS OCR PA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Service & Access Management, Inc.
- Normalized
- service access management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🦀Maryland State AGas victim2025-02-27
Service Access & Management, Inc. notified the Maryland AG of a data security incident discovered on July 5, 2024. An unauthorized user accessed systems, affecting 17 Maryland residents with names, SSNs, and medical information. SAM engaged forensic specialists, reset credentials, rebuilt systems, and offered 12 months of credit monitoring.
- 🦞Maine State AGas victim2025-02-27
Service Access & Management, Inc. (SAM), a nonprofit human services organization in Pennsylvania and New Jersey, discovered suspicious activity on its network on July 5, 2024. An unauthorized user potentially accessed SAM's systems. By September 12, 2024, affected files were identified; a review completed January 31, 2025 confirmed some PII may have been exposed. Four Maine residents were affected. Notifications were sent February 27, 2025. IDX credit monitoring was offered.
- 🍁Vermont State AGas victim2025-02-27
Service Access & Management, Inc. (SAM), a nonprofit human services provider, notified consumers of a data security incident discovered on July 5, 2024. An unauthorized user potentially accessed SAM's systems, impacting names and variable data elements. SAM engaged forensic experts, reset passwords, notified law enforcement, and offered credit monitoring via IDX. No evidence of misuse was found at the time of notification.
- PAHHS OCRas victim2024-09-02
Service Access & Management, Inc. (PA) reported to HHS on 2024-09-02 a Hacking/IT Incident (ransomware) affecting 1,450 individuals. Breached information was located on a Network Server. PHI involved included names, addresses, dates of birth, Social Security and driver's license numbers, medical information, and health insurance information. The entity notified HHS, impacted individuals, the media, and posted a substitute notice. OCR provided technical assistance regarding the HIPAA Rules.