OneTouchPoint, Inc.
ent_d06e9cea19c6ae367ae1e5c0
Disclosures
13
State AG · HHS OCR · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
4,112,892
nationwide · HHS OCR WI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- OneTouchPoint, Inc.
- Normalized
- onetouchpoint— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- onetouchpoint.com
Disclosure history (13)newest first
- 🦞Maine State AGas victim2022-08-26
OneTouchPoint, Inc. experienced an external system breach between April 27 and April 28, 2022. The breach was discovered on July 15, 2022. The incident resulted in the acquisition of names and Social Security Numbers. Notification to affected individuals was sent on August 26, 2022, and the company offered credit monitoring and identity theft protection services.
- 🐻California State AGas victim2022-08-12
OneTouchPoint, Inc. (OTP), a printing and mailing services vendor for health insurers and providers, experienced a security breach involving unauthorized access to its servers beginning April 27, 2022. OTP discovered encrypted files on April 28, 2022, indicating a ransomware attack. While specific file contents were undetermined, impacted systems contained personal information (PII). OTP engaged third-party forensic specialists, notified law enforcement, and sent breach notifications to affected individuals starting June 3, 2022. No evidence of misuse was found, and business customers' systems were not impacted.
- 🦬Montana State AGas victim2022-08-01
OneTouchPoint, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2022-08-01. The breach occurred on 4/27/2022. 35 Montana residents were affected.
- 🐻California State AGas reporting2022-08-01
CareSource reported a cybersecurity incident involving its third-party vendor, OneTouchPoint (OTP). On April 28, 2022, OTP systems were locked by an attacker, indicating a ransomware attack. Files containing member personal information (names, addresses, member IDs, age, gender) and health data (diagnoses, medications, allergies, health screenings, vital signs, immunizations, plan names) were encrypted. OTP shut down and rebuilt systems, adding technical controls. No SSN or financial account data was impacted.
- 🦬Montana State AGas victim2022-07-27
OneTouchPoint, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2022-07-27. The breach occurred from 4/27/2022 to 4/28/2022. 74 Montana residents were affected.
- 💎Delaware State AGas reporting2022-07-27
OneTouchPoint, Inc. (OTP), a vendor for Matrix Medical Network, experienced a ransomware incident on April 27, 2022, discovered on April 28, 2022. Encrypted files were found on OTP systems. The incident affected approximately 1,073,316 individuals nationwide, including 7 Delaware residents. Data potentially accessed included names, member IDs, and health assessment information. OTP engaged forensic specialists, notified law enforcement, and implemented additional safeguards. Notifications to affected individuals began July 27, 2022.
- 🐻California State AGas reporting2022-07-27
Aetna, via its vendor OneTouchPoint, Inc. (OTP), disclosed a ransomware incident discovered on April 28, 2022. Unauthorized access to OTP servers began April 27, 2022, resulting in encrypted files. OTP engaged forensic specialists and law enforcement. Customer data, including names and specific data elements, was present on impacted servers; Social Security numbers were not affected. Notification was sent to affected individuals starting June 3, 2022. No evidence of misuse was found.
- 🦫Oregon State AGas victim2022-07-27
One Touchpoint, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-07-27. The breach occurred during 4/27/2022 - 4/28/2022. The breach was discovered on 6/3/2022. 1,073,316 individuals were affected. Notice was sent on 7/27/2022.
- 🦞Maine State AGas victim2022-07-27
OneTouchPoint, Inc. reported an external system breach (hacking) occurring April 27-28, 2022, discovered June 3, 2022. The incident affected approximately 1,073,316 individuals, including 7 Maine residents. The breach involved the acquisition of names and personal identifiers. Written notification was sent on July 27, 2022. No identity theft protection services were offered.
- WISCONSINHHS OCRas victim2022-07-27
OneTouchPoint, Inc. reported to HHS on 2022-07-27 a Hacking/IT Incident affecting 4,112,892 individuals. Breached information located on Network Server. The business associate experienced a ransomware attack affecting PHI including names, addresses, dates of birth, diagnoses, and medications. The BA implemented additional administrative, technical, and security safeguards.
- 🌲Washington State AGas victim2022-07-27
OneTouchPoint, Inc., a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2022-04-28 and filed notice on 2022-07-27. 1,321 Washington residents were affected. 90 days elapsed between awareness and notification. 1 days to identify the breach. 0 days to contain the breach.
- 💎Delaware State AGas victim2022-07-27
Matrix Medical Network reported a cybersecurity incident involving its vendor, OneTouchPoint, Inc. (OTP). OTP discovered encrypted files (ransomware) on its systems on April 28, 2022, with unauthorized access beginning April 27, 2022. The incident affected approximately 1,073,316 individuals nationwide, including 7 Delaware residents. Data potentially accessed included names, member IDs, and health assessment information. OTP notified law enforcement, engaged forensic specialists, and sent notices to affected individuals starting July 27, 2022.
- 💎Delaware State AGas victim2022-06-03
State AG breach notification from One Touch Point, Inc. in Delaware. The attached PDF content is empty (placeholder text only), preventing extraction of breach specifics, dates, or data types.