Healthfirst
ent_7392f6c7f66b19f452dcd515
Disclosures
4
State AG · HHS OCR · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
6,836
nationwide · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Healthfirst
- Normalized
- healthfirst— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- healthfirst.org
Disclosure history (4)newest first
- Texas State AGas victim2026-08-28
Healthfirst Bluegrass, Inc. based in Lexington, Kentucky, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-08-13 and reported on 2026-08-28. 312 Texas residents were affected. 139,834 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Date of Birth. Consumers were notified via U.S. Mail.
- NEW YORKHHS OCRas victim2024-03-13
Healthfirst, a New York-based Health Plan, reported to HHS OCR on 2024-03-13 a ransomware incident affecting the PHI of 6,836 individuals. Breached information was located on a Network Server. PHI exposed included names, addresses, and dates of birth. The CE notified HHS, affected individuals, and the media, posted substitute notice on its website, offered free credit monitoring, and implemented additional safeguards and staff training.
- NEW YORKHHS OCRas victim2022-05-09
Healthfirst reported to HHS on 2022-05-09 a Unauthorized Access/Disclosure affecting 5048 individuals. Breached information located on Paper/Films. A software misconfiguration caused PHI (names, phone numbers, health insurance info) to be sent to wrong recipients. CE provided credit monitoring, revised policies, and retrained employees.
- NEW YORKHHS OCRas victim2019-05-24
Healthfirst reported to HHS on 2019-05-24 a Unauthorized Access/Disclosure affecting 1811 individuals. Breached information located on Paper/Films. Employees sent letters containing PHI (names, birthdates, diagnoses, treatment) to wrong addresses. CE implemented administrative safeguards and retrained staff.