BAESMAN GROUP
ent_6df04eabcd891ce82cb8fc39
Disclosures
8
State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,170,094
nationwide · HHS OCR OH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BAESMAN GROUP
- Normalized
- baesman group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- Oregon State AGas victim2024-02-29
Baesman Group, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-02-29. The breach occurred during 5/29/2023 - 5/29/2023. The breach was discovered on 5/31/2023. 863,812 individuals were affected. Notice was sent on 2/29/2024.
- California State AGas victim2024-02-29
Baesman Group, Inc. experienced a data security incident occurring between May 29, 2023 and June 21, 2023. The organization filed a breach notification with the California Attorney General. Approximately 68 Rhode Island residents were noted as potentially impacted. The attachment contained limited extracted text; full details on data types and response actions were not available in the extracted content.
- Washington State AGas victim2024-02-29
Baesman Group, Inc. disclosed a cybersecurity incident involving the MOVEit application. Unauthorized access occurred on May 29, 2023. The breach impacted PII, PHI, and government IDs of 1,658 Washington residents and others. Notices began August 17, 2023, with supplemental notices in February 2024.
- Massachusetts State AGas victim2024-02-29
Baesman Group, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-02-29. 1,524 Massachusetts residents were affected.
- California State AGas victim2024-02-12
Baesman Group, Inc. notified the California AG of a data breach involving unauthorized access to a third-party MOVEit Transfer server on May 29, 2023. An unknown actor exploited security issues in Progress Software's MOVEit tool to access and exfiltrate data. Affected individuals' names and health-related data were involved. Baesman Group is a service provider to health plans administered by Elevance Health entities. The company launched an investigation, reviewed impacted data, and is enhancing privacy policies.
- Montana State AGas victim2024-02-05
Baesman Group, Inc. notified HealthSun Health Plans members of unauthorized access to a MOVEit Transfer server on May 29, 2023. The attacker exfiltrated PII including names, addresses, DOBs, and member IDs. Baesman Group investigated and enhanced privacy policies. Notices were sent on February 5, 2024.
- Illinois State AGas victim2024-02-01
BAESMAN GROUP filed a data-breach notice with the Illinois Attorney General in February 2024 (case 24-02-249). The register records the breach as discovered on May 31, 2024. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- OHIOHHS OCRas victim2023-08-17
Baesman Group, Inc. reported to HHS on 2023-08-17 a Hacking/IT Incident affecting 1,170,094 individuals. Breached information located on Network Server. A software application exposed PHI including names, dates of birth, and addresses. The BA notified HHS, affected individuals, and the media, and provided substitute notice. The BA strengthened administrative and technical safeguards.
Supply-chain cascadesreviewed and confirmed
- BAESMAN GROUP’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).