Hafetz and Associates
ent_46a56ef67911d01c5f21a78f
Disclosures
3
HHS OCR · State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
26,474
as filed · HHS OCR NJ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Hafetz and Associates
- Normalized
- hafetz and associates— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Aon— per SEC Exhibit 21 filing
Disclosure history (3)newest first
- NJHHS OCRas victim2024-09-27
Hafetz and Associates (NJ), a HIPAA-covered entity, reported a phishing-based hacking/IT incident affecting email accounts of multiple employees and the PHI of 26,474 individuals. Compromised data included names, dates of birth, SSNs, driver's license numbers, addresses, medications, claims and financial information, and health insurance information. The entity notified HHS, affected individuals, the media, and posted substitute notice; remediation included additional administrative, technical, and security safeguards.
- 🏎️Indiana State AGas victim2024-06-28
Hafetz & Associates reported a data breach to the Indiana Attorney General. The breach occurred on 2023-07-24 and was reported on 2024-06-28. 1 Indiana residents were affected. 2,391 individuals affected in total.
- ⛰️New Hampshire State AGas victim2024-06-28
Hafetz & Associates notified the NH Attorney General of a phishing incident resulting in unauthorized access to employee email accounts between July 24 and October 12, 2023. One NH resident's name was exposed. Hafetz blocked access, investigated, and mailed notifications on June 28, 2024, offering two years of credit monitoring via Kroll.