Point32Health
ent_9affc28db6f812c1cdf7ba20
Massachusetts publishes one register entry per notified resident. Point32Health filed 2 breach notifications with the Massachusetts OCA, 2 of them covering a single resident. The register records who filed and how many residents — not where the breach occurred.
Disclosures
3
State AG · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
1
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Point32Health
- Normalized
- point32health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- point32health.org
Disclosure history (3)newest first
- Massachusetts State AGas victim2025-08-27
Point32Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-08-27. 1 Massachusetts residents were affected.
- Massachusetts State AGas victim2024-11-27
Point32Health, Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-11-27. 1 Massachusetts residents were affected.
- New Hampshire State AGas victim2023-06-30
Point32Health, a business associate of Health Plans, Inc., experienced a ransomware incident detected on April 17, 2023. Unauthorized access occurred between March 28 and April 17, 2023, resulting in data copying. Affected data includes PII and PHI of HPI subscribers. Point32Health engaged forensic experts, notified law enforcement, and is offering credit monitoring. Investigation was active as of the notice date.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of Point32Health — not by Point32Health itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Illinois State AGvia Harvard Pilgrim Health Care2026-07-01
HARVARD PILGRIM HEALTH CARE, INC. filed a data-breach notice with the Illinois Attorney General in July 2026 (case 26-07-1328). The register records the breach as discovered on June 2, 2026. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Maine State AGvia Harvard Pilgrim Health Care2026-01-14
Harvard Pilgrim Health Care reported a cybersecurity incident involving its subcontractor, Conduent Business Services. Unauthorized access occurred from October 21, 2024, to January 13, 2025. Conduent discovered the breach on January 13, 2025, and notified Harvard Pilgrim. The incident affected 505 individuals, including 4 Maine residents. Personal information, including names and other identifiers, was accessed. Conduent engaged forensic experts, secured networks, and notified law enforcement. Affected individuals were offered 12 months of credit monitoring.
- Maryland State AGvia Harvard Pilgrim Health Care2025-11-13
Supplemental security breach notification filed by Mullen Coughlin LLC on behalf of Harvard Pilgrim Health Care with the Maryland Attorney General. A ransomware incident occurred between March 28, 2023, and April 17, 2023. The breach compromised personal information (names, addresses, DOB, SSN) and protected health information (clinical records, diagnoses) for approximately 8 Maryland residents in this specific supplemental notice. The investigation is ongoing.
- Massachusetts State AGvia Harvard Pilgrim Health Care2025-05-09
Harvard Pilgrim Health Care reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-05-09. 1 Massachusetts residents were affected.
- Massachusetts State AGvia Harvard Pilgrim Health Care2025-03-28
Harvard Pilgrim Health Care reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-03-28. 1 Massachusetts residents were affected.
- Massachusetts State AGvia Harvard Pilgrim Health Care2025-03-04
Harvard Pilgrim Health Care reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-03-04. 1 Massachusetts residents were affected.
- Rhode Island State AGvia Harvard Pilgrim Health Care2025-01-27
Harvard Pilgrim Health Care filed a supplemental notice with the Rhode Island Attorney General regarding a ransomware incident discovered on April 17, 2023. Unauthorized access occurred from March 28 to April 17, 2023, resulting in the copying of personal and protected health information (including SSNs, DOBs, and clinical data) for approximately 34,336 Rhode Island residents. The investigation is ongoing, and the company has engaged forensic experts and implemented additional safeguards.
- California State AGvia Harvard Pilgrim Health Care2025-01-21
Harvard Pilgrim Health Care experienced a ransomware incident. Unauthorized access occurred between March 28, 2023, and April 17, 2023. The organization discovered the incident on April 17, 2023. Data was copied and taken from systems. Affected data includes names, addresses, dates of birth, health insurance account information, and clinical information (diagnoses, treatments). This is a supplemental notice sent in January 2025. Two years of credit monitoring are offered.
- Vermont State AGvia Harvard Pilgrim Health Care2025-01-21
Harvard Pilgrim Health Care disclosed a ransomware incident affecting systems used to service members, accounts, brokers, and providers. The breach occurred between March 28 and April 17, 2023. Data copied included names, addresses, DOBs, health insurance account info, and clinical data. Approximately 34,336 Rhode Island residents were identified as potentially impacted. The company engaged forensic experts, notified law enforcement, and offered two years of credit monitoring.
- Delaware State AGvia Harvard Pilgrim Health Care2024-10-03
Harvard Pilgrim Health Care, a subsidiary of Point32Health, issued a supplemental notice regarding a ransomware incident discovered on April 17, 2023. The attack impacted systems servicing members, accounts, brokers, and providers. Data was copied between March 28 and April 17, 2023. The notice specifically identifies approximately 1,347 Rhode Island residents as potentially affected. Harvard Pilgrim took systems offline, engaged forensic experts, and is offering two years of credit monitoring.