Aya Healthcare
ent_1c8b558341b1fca72de4974a
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,187
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Aya Healthcare
- Normalized
- aya healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- ayahealthcare.com
Disclosure history (7)newest first
- Indiana State AGas victim2025-02-27
Aya Healthcare Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-01-12 and was reported on 2025-02-27. 102 Indiana residents were affected.
- Montana State AGas victim2025-02-27
Aya Healthcare, Inc. notified individuals of a data security incident where unauthorized third parties used stolen credentials (obtained from unrelated sources) to access user accounts. The breach, discovered on January 12, 2025, involved an automated bot viewing limited personal information including names, SSNs, and license numbers. Aya engaged cybersecurity experts, reset passwords, and offered 24 months of credit monitoring.
- Maryland State AGas victim2025-02-27
Aya Healthcare, Inc. notified Maryland AG of a data security incident where unauthorized third parties used stolen credentials (obtained from unrelated sources) to access user accounts. The breach involved automated bot access to limited personal information including names, contact info, SSNs, and nursing license numbers. Aya reset passwords and offered 24 months of credit monitoring.
- Massachusetts State AGas victim2025-02-27
Aya Healthcare, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-02-27. 32 Massachusetts residents were affected.
- Maine State AGas victim2025-02-27
Aya Healthcare, Inc. reported a data breach where unauthorized third parties used stolen credentials (usernames/passwords from unrelated sources) to access user accounts between Jan 12-19, 2025. Discovered Jan 29, 2025. Affected 3,187 individuals, including 4 Maine residents. Data accessed included names, contact info, SSNs, license numbers, and DOBs. No evidence of misuse. Notifications sent Feb 27, 2025, offering 24 months of credit monitoring.
- Nebraska State AGas victim2025-02-27
Aya Healthcare, Inc. notified Nebraska residents of a data security incident where unauthorized third parties used stolen credentials from other sources to gain access to user accounts. The breach occurred in January 2025, affecting names, SSNs, license numbers, and health data. Aya reset passwords, engaged cybersecurity experts, and offered 24 months of credit monitoring.
- Vermont State AGas victim2025-02-27
Aya Healthcare, Inc. notified consumers that unauthorized third parties used credentials obtained from unrelated sources to access user accounts via automated bots on January 12 and 19, 2025. Affected data included names, contact info, SSNs, nursing license numbers, and vaccination status. Aya reset passwords and offered 24 months of credit monitoring.