Healthfirst
ent_1af34b2709c953885453e458
Disclosures
3
HHS OCR · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
6,836
as filed · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Healthfirst
- Normalized
- healthfirst— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- NEW YORKHHS OCRas victim2024-03-13
Healthfirst, a New York-based Health Plan, reported to HHS OCR on 2024-03-13 a ransomware incident affecting the PHI of 6,836 individuals. Breached information was located on a Network Server. PHI exposed included names, addresses, and dates of birth. The CE notified HHS, affected individuals, and the media, posted substitute notice on its website, offered free credit monitoring, and implemented additional safeguards and staff training.
- NEW YORKHHS OCRas victim2022-05-09
Healthfirst reported to HHS on 2022-05-09 a Unauthorized Access/Disclosure affecting 5048 individuals. Breached information located on Paper/Films. A software misconfiguration caused PHI (names, phone numbers, health insurance info) to be sent to wrong recipients. CE provided credit monitoring, revised policies, and retrained employees.
- NEW YORKHHS OCRas victim2019-05-24
Healthfirst reported to HHS on 2019-05-24 a Unauthorized Access/Disclosure affecting 1811 individuals. Breached information located on Paper/Films. Employees sent letters containing PHI (names, birthdates, diagnoses, treatment) to wrong addresses. CE implemented administrative safeguards and retrained staff.