OneTouchPoint, Inc.
ent_d06e9cea19c6ae367ae1e5c0
Disclosures
14
State AG · HHS OCR · 11 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,112,892
nationwide · HHS OCR WI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- OneTouchPoint, Inc.
- Normalized
- onetouchpoint— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- onetouchpoint.com
Disclosure history (14)newest first
- Maine State AGas victim2022-08-26
OneTouchPoint, Inc. experienced an external system breach between April 27 and April 28, 2022. The breach was discovered on July 15, 2022. The incident resulted in the acquisition of names and Social Security Numbers. Notification to affected individuals was sent on August 26, 2022, and the company offered credit monitoring and identity theft protection services.
- California State AGas victim2022-08-12
OneTouchPoint, Inc. discovered encrypted files on April 28, 2022, indicating unauthorized access to servers starting April 27, 2022. The company, a vendor for health insurance carriers and medical providers, engaged forensic specialists and notified law enforcement. While specific accessed files could not be determined, customer information was present on impacted systems. No evidence of misuse was found.
- Montana State AGas victim2022-08-01
OneTouchPoint, Inc. notified Montana residents of a cybersecurity incident discovered on April 28, 2022, where attacker-locked files containing personal and health information (names, diagnoses, medications, etc.) were accessed. Systems were shut down and rebuilt; no evidence of data removal was found.
- South Carolina State AGas victim2022-07-28
OneTouchPoint, Inc. notified South Carolina residents of a ransomware incident discovered on April 28, 2022, involving unauthorized access to servers beginning April 27, 2022. The incident impacted health assessment data, names, and member IDs. OTP engaged forensic specialists and notified law enforcement. No evidence of misuse was found.
- Montana State AGas victim2022-07-27
OneTouchPoint, Inc. notified Montana residents of a ransomware incident discovered on April 28, 2022, involving unauthorized access to servers beginning April 27, 2022. Encrypted files were found. Affected data included names, member IDs, and health assessment information. No SSN or financial data was impacted. The company engaged forensic specialists and notified law enforcement.
- Delaware State AGas reporting2022-07-27
OneTouchPoint, Inc. (OTP), a vendor for Matrix Medical Network, experienced a ransomware incident on April 27, 2022, discovered on April 28, 2022. Encrypted files were found on OTP systems. The incident affected approximately 1,073,316 individuals nationwide, including 7 Delaware residents. Data potentially accessed included names, member IDs, and health assessment information. OTP engaged forensic specialists, notified law enforcement, and implemented additional safeguards. Notifications to affected individuals began July 27, 2022.
- Oregon State AGas victim2022-07-27
One Touchpoint, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-07-27. The breach occurred during 4/27/2022 - 4/28/2022. The breach was discovered on 6/3/2022. 1,073,316 individuals were affected. Notice was sent on 7/27/2022.
- Maine State AGas victim2022-07-27
OneTouchPoint, Inc. reported an external system breach (hacking) occurring April 27-28, 2022, discovered June 3, 2022. The incident affected approximately 1,073,316 individuals, including 7 Maine residents. The breach involved the acquisition of names and personal identifiers. Written notification was sent on July 27, 2022. No identity theft protection services were offered.
- WISCONSINHHS OCRas victim2022-07-27
OneTouchPoint, Inc. reported to HHS on 2022-07-27 a Hacking/IT Incident affecting 4,112,892 individuals. Breached information located on Network Server. The business associate experienced a ransomware attack affecting PHI including names, addresses, dates of birth, diagnoses, and medications. The BA implemented additional administrative, technical, and security safeguards.
- Washington State AGas victim2022-07-27
OneTouchPoint, Inc. notified Washington AG of a ransomware incident affecting 1,321 Washington residents. Unauthorized access began April 27, 2022, and was discovered April 28, 2022. Encrypted files were found, and data including names, member IDs, and health assessment info was potentially accessed. Notices sent July 27, 2022.
- Massachusetts State AGas victim2022-07-27
OneTouchPoint, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-07-27. 113,811 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2022-07-27
One TouchPoint, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-04-27 and was reported on 2022-07-27. 73,466 Indiana residents were affected. 1,073,316 individuals affected in total.
- Delaware State AGas victim2022-06-03
OneTouchPoint, Inc. notified individuals of a data event where unauthorized access to its servers occurred on April 27, 2022, discovered on April 28, 2022. Encrypted files indicated ransomware. Affected data included names, member IDs, and health assessment info. No SSN or financial data impacted. OTP engaged forensic specialists and notified law enforcement.
- Illinois State AGas victim2022-01-01
ONE TOUCH POINT LLC filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-469). The register records the breach as discovered on April 28, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.