Benefit Plan Administrators, Inc.
ent_6473d3f48692e0345c359b41
Disclosures
11
HHS OCR · State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
5,004
nationwide · HHS OCR VA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Benefit Plan Administrators, Inc.
- Normalized
- benefit plan administrators— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (11)newest first
- VIRGINIAHHS OCRas victim2022-07-25
Benefit Plan Administrators, Inc. reported to HHS on 2022-07-25 a Hacking/IT Incident affecting 1,457 individuals. Breached information located on Network Server. The incident involved PHI including names, addresses, DOB, SSNs, claims, medications, and diagnoses. The BA provided credit monitoring and implemented additional safeguards.
- VIRGINIAHHS OCRas victim2022-07-22
Benefit Plan Administrators, Inc. (a Business Associate, VA) reported to HHS OCR on 2022-07-22 a Hacking/IT Incident affecting 5,004 individuals. Breached information was located on a Network Server. Compromised PHI included names, addresses, dates of birth, Social Security numbers, gender, claims information, medications, and diagnoses. In response, the BA provided complimentary credit monitoring and implemented additional administrative, technical, and security safeguards.
- VIRGINIAHHS OCRas victim2022-07-08
Benefit Plan Administrators, Inc. reported to HHS on 2022-07-08 a Hacking/IT Incident affecting 878 individuals. Breached information located on Network Server. The incident involved PHI including names, addresses, DOB, SSNs, claims, medications, and diagnoses.
- VIRGINIAHHS OCRas victim2022-07-08
Benefit Plan Administrators, Inc. reported to HHS on 2022-07-08 a Hacking/IT Incident affecting 1089 individuals. Breached information located on Network Server. The business associate experienced a cyber-attack compromising PHI including names, addresses, DOB, SSNs, claims, medications, and diagnoses. Response included complimentary credit monitoring and implementation of additional safeguards.
- VIRGINIAHHS OCRas victim2022-06-30
Benefit Plan Administrators, Inc. reported to HHS on 2022-06-30 a Hacking/IT Incident affecting 628 individuals. Breached information located on Network Server. The cyber-attack compromised PHI including names, addresses, DOB, SSNs, claims, medications, and diagnoses. The BA provided credit monitoring and implemented safeguards.
- South Carolina State AGas victim2022-06-29
Benefit Plan Administrators, Inc. notified South Carolina and other states of a September 13, 2021 unauthorized network access. Files containing PII (name, SSN, DOB) and PHI (claims, medications, diagnoses) were potentially removed. The company engaged outside cybersecurity professionals and offered Equifax Credit Watch Gold. No identity fraud reported to date.
- VIRGINIAHHS OCRas victim2022-06-29
Benefit Plan Administrators, Inc. reported to HHS on 2022-06-29 a Hacking/IT Incident affecting 1145 individuals. Breached information located on Network Server. The incident compromised PHI including names, addresses, DOB, SSNs, claims, medications, and diagnoses.
- VIRGINIAHHS OCRas victim2022-06-27
Benefit Plan Administrators, Inc. reported to HHS on 2022-06-27 a Hacking/IT Incident affecting 735 individuals. Breached information located on Network Server. The business associate experienced a cyber-attack compromising PHI including names, addresses, DOB, SSNs, claims, medications, and diagnoses. Response included credit monitoring and enhanced safeguards.
- VIRGINIAHHS OCRas victim2022-06-27
Benefit Plan Administrators, Inc. (a business associate based in VA) reported to HHS OCR on 2022-06-27 that a cyber-attack on a network server compromised PHI of 1,267 individuals. Exposed data included names, addresses, dates of birth, Social Security numbers, gender, claims information, medications, and diagnoses. The BA offered complimentary credit monitoring and implemented additional administrative, technical, and security safeguards. Exact attack technique (e.g., ransomware vs. unauthorized access) is not specified in the OCR summary.
- New Hampshire State AGas victim2022-06-27
Benefit Plan Administrators, Inc. notified the NH Attorney General of unauthorized network access on or about September 13, 2021. The incident potentially exposed personal and PHI of 5 NH residents, including names, SSNs, and medical data. Notification to affected individuals began June 15, 2022, offering 12 months of credit monitoring.
- Illinois State AGas victim2022-01-01
BENEFIT PLAN ADMINISTRATORS filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-418). The register records the breach as discovered on September 13, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.