Harvard Pilgrim Health Care
ent_d13b12236492cb73946c1690
Disclosures
25+
State AG · 7 jurisdictions
Incidents
4
filings grouped by incident
Max affected reported
2,860,795
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Harvard Pilgrim Health Care
- Normalized
- harvard pilgrim health care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- point32health.org
Disclosure history (newest 25)newest first
- 🦞Maine State AGas victim2026-01-14
Harvard Pilgrim Health Care reported that a subcontractor experienced a cybersecurity incident, resulting in the exposure of member data. The breach, described as an external system breach (hacking), occurred on October 21, 2024, and was discovered on September 15, 2025. A total of 505 individuals were affected, including 4 residents of Maine. Affected individuals were notified on October 31, 2025, and offered 12 months of credit monitoring services.
- 🦀Maryland State AGas victim2025-11-13
Supplemental security breach notification filed by Mullen Coughlin LLC on behalf of Harvard Pilgrim Health Care with the Maryland Attorney General. A ransomware incident occurred between March 28, 2023, and April 17, 2023. The breach compromised personal information (names, addresses, DOB, SSN) and protected health information (clinical records, diagnoses) for approximately 8 Maryland residents in this specific supplemental notice. The investigation is ongoing.
- 🐻California State AGas victim2025-01-21
Harvard Pilgrim Health Care experienced a ransomware incident. Unauthorized access occurred between March 28, 2023, and April 17, 2023. The organization discovered the incident on April 17, 2023. Data was copied and taken from systems. Affected data includes names, addresses, dates of birth, health insurance account information, and clinical information (diagnoses, treatments). This is a supplemental notice sent in January 2025. Two years of credit monitoring are offered.
- 🍁Vermont State AGas victim2025-01-21
Harvard Pilgrim Health Care disclosed a ransomware incident affecting systems used to service members, accounts, brokers, and providers. The breach occurred between March 28 and April 17, 2023. Data copied included names, addresses, DOBs, health insurance account info, and clinical data. Approximately 34,336 Rhode Island residents were identified as potentially impacted. The company engaged forensic experts, notified law enforcement, and offered two years of credit monitoring.
- 💎Delaware State AGas victim2024-10-03
Harvard Pilgrim Health Care, a subsidiary of Point32Health, issued a supplemental notice regarding a ransomware incident discovered on April 17, 2023. The attack impacted systems servicing members, accounts, brokers, and providers. Data was copied between March 28 and April 17, 2023. The notice specifically identifies approximately 1,347 Rhode Island residents as potentially affected. Harvard Pilgrim took systems offline, engaged forensic experts, and is offering two years of credit monitoring.
- 🦞Maine State AGas victim2024-10-03
Harvard Pilgrim Health Care reported a data breach to the Maine Attorney General, indicating that an external system breach (hacking) occurred on March 28, 2023. The breach was discovered on April 17, 2023, and affected 210,354 Maine residents. The company offered credit monitoring services to those affected.
- 🐻California State AGas victim2024-10-03
Harvard Pilgrim Health Care experienced a ransomware incident discovered on April 17, 2023. Unauthorized access occurred between March 28 and April 17, 2023, during which data was copied and taken from systems. The incident involved personal information and protected health information (PHI) of members, accounts, brokers, and providers. Systems were taken offline to contain the threat. Third-party forensic experts were engaged. Additional cybersecurity safeguards were implemented. Affected individuals are offered two years of complimentary credit monitoring and identity protection services.
- ⛰️New Hampshire State AGas victim2024-10-03
Harvard Pilgrim Health Care disclosed a ransomware incident discovered on April 17, 2023. Unauthorized access occurred between March 28 and April 17, 2023, resulting in data exfiltration. The company determined on August 15, 2024, that affected files contained personal and protected health information. The organization engaged forensic experts, notified law enforcement, and implemented additional cybersecurity safeguards.
- 🦞Maine State AGas victim2024-03-27
Harvard Pilgrim Health Care, a healthcare organization, reported a data breach affecting over 2.8 million individuals. The incident, an external system breach (hacking), occurred on March 28, 2023, and was discovered on April 17, 2023. The compromised information includes names and Social Security numbers. Notification to affected individuals was sent on March 27, 2024.
- 💎Delaware State AGas victim2024-03-27
Harvard Pilgrim Health Care, a subsidiary of Point32Health, disclosed a ransomware incident discovered on April 17, 2023. The attack impacted systems servicing members, accounts, brokers, and providers. Data was copied between March 28 and April 17, 2023, potentially exposing personal information including names, Social Security numbers, dates of birth, and driver's license numbers. Approximately 9,766 Rhode Island residents were specifically identified as impacted. The company took systems offline, notified law enforcement, engaged forensic experts, and offered two years of credit monitoring.
- ⛰️New Hampshire State AGas victim2024-03-27
Harvard Pilgrim Health Care disclosed a ransomware incident discovered on April 17, 2023. Unauthorized access occurred between March 28 and April 17, 2023, resulting in data exfiltration. Personal information of members, including names and addresses, was potentially compromised. The company engaged forensic experts, notified law enforcement, and offered credit monitoring services.
- 🐻California State AGas victim2024-03-27
Harvard Pilgrim Health Care disclosed a ransomware incident where an unauthorized party accessed systems from March 28 to April 17, 2023. The organization discovered the incident on April 17, 2023, and took systems offline to contain the threat. Investigation confirmed data was copied and taken. This supplemental notice informs affected individuals, including approximately 9,766 Rhode Island residents, about the potential exposure of personal and health information. Credit monitoring services are being offered.
- 🍁Vermont State AGas victim2024-03-27
Harvard Pilgrim Health Care disclosed a ransomware incident discovered on April 17, 2023, affecting systems servicing members and providers. Data was copied between March 28 and April 17, 2023. The notice, filed in Vermont on March 27, 2024, specifically identifies approximately 9,766 Rhode Island residents as potentially impacted. Affected data includes personal information such as names and government IDs. The company engaged forensic experts, took systems offline, and offered two years of credit monitoring.
- ⛰️New Hampshire State AGas victim2024-02-15
Harvard Pilgrim Health Care reported a ransomware incident discovered on April 17, 2023. Unauthorized access led to data copying. The company took systems offline, engaged forensic experts, and notified law enforcement. Personal information, potentially including SSNs, was involved. Notices were sent on Feb 15, 2024, offering credit monitoring. At least 1,347 Rhode Island residents were impacted.
- 🐻California State AGas victim2024-02-15
Harvard Pilgrim Health Care disclosed a ransomware incident where an unauthorized party accessed systems from March 28 to April 17, 2023. The organization discovered the incident on April 17, 2023, and took systems offline. Investigation confirmed data was copied and taken. This supplemental notice informs affected individuals, including California and Rhode Island residents, that their personal and health information may have been involved. Credit monitoring services are being provided.
- 💎Delaware State AGas victim2024-02-15
Harvard Pilgrim Health Care, a subsidiary of Point32Health, issued a supplemental notice regarding a ransomware incident discovered on April 17, 2023. The attack occurred between March 28 and April 17, 2023, resulting in the encryption of systems and exfiltration of personal information, including names, SSNs, and dates of birth. Approximately 1,347 Rhode Island residents were identified as potentially affected. The company took systems offline, engaged forensic experts, and offered two years of credit monitoring.
- 🦞Maine State AGas victim2024-02-15
Harvard Pilgrim Health Care reported an external system breach (hacking) occurring on March 28, 2023, discovered on April 17, 2023. The incident affected 2,632,275 individuals, including 993 Maine residents. Acquired data included names and Social Security Numbers. The company provided written notifications and offered 24 months of identity theft protection services.
- 🐻California State AGas victim2023-08-25
Harvard Pilgrim Health Care experienced a ransomware incident affecting systems used to service clients, including UnitedHealthcare. Unauthorized access occurred between March 28, 2023, and April 17, 2023, with discovery on April 17, 2023. Data exfiltrated included names, addresses, SSNs, health insurance account info, and clinical information. Systems were taken offline, and forensic experts were engaged. Credit monitoring is offered.
- 🦞Maine State AGas victim2023-08-25
Harvard Pilgrim Health Care reported a data breach affecting 2,550,922 individuals, including 875 Maine residents. The breach, discovered on April 17, 2023, occurred on March 28, 2023, and was described as an external system breach or hacking incident. The compromised information included names and Social Security numbers. Affected individuals were notified on August 25, 2023, and offered 24 months of credit monitoring services through IDX.
- 🌲Washington State AGas victim2023-08-25
United Health Care (Harvard Pilgrim Health Care), a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-04-17 and filed notice on 2023-08-25. 1,025 Washington residents were affected. 130 days elapsed between awareness and notification. 20 days to identify the breach. 0 days to contain the breach.
- 🍁Vermont State AGas victim2023-08-25
Harvard Pilgrim Health Care disclosed a ransomware incident discovered on April 17, 2023, affecting systems used for client services. Data copied between March 28 and April 17, 2023, included PII and PHI (names, SSNs, DOBs, clinical info). The company took systems offline, engaged forensic experts, and offered 2 years of credit monitoring. Approximately 22,365 Rhode Island residents were identified as impacted.
- ⛰️New Hampshire State AGas victim2023-08-24
Harvard Pilgrim Health Care reported a ransomware incident discovered on April 17, 2023, affecting systems used to service clients including UnitedHealthcare. Unauthorized access occurred between March 28 and April 17, 2023, resulting in data exfiltration. The files contained personal and protected health information. The company engaged forensic experts, notified law enforcement, and implemented additional cybersecurity safeguards. Credit monitoring services were offered to affected individuals.
- 💎Delaware State AGas victim2023-08-15
Harvard Pilgrim Health Care, a subsidiary of Point32Health, disclosed a ransomware incident discovered on April 17, 2023, affecting systems used to service clients including UnitedHealthcare. The breach impacted data from March 28 to April 17, 2023, involving names, SSNs, DOBs, and clinical information. Approximately 22,365 Rhode Island residents were identified as potentially affected. The company took systems offline, engaged forensic experts, and offered two years of credit monitoring.
- 🐻California State AGas victim2023-07-20
Harvard Pilgrim Health Care experienced a ransomware incident discovered on April 17, 2023. Unauthorized access occurred between March 28 and April 17, 2023, during which data was copied and exfiltrated. Affected data includes PHI, PII, SSNs, and health insurance account information. Systems were taken offline to contain the threat. Third-party experts were engaged. Credit monitoring offered.
- ⛰️New Hampshire State AGas victim2023-07-20
Harvard Pilgrim Health Care reported a ransomware incident discovered on April 17, 2023, affecting systems servicing members and providers. Unauthorized access occurred between March 28 and April 17, 2023, resulting in data exfiltration. Personal information and protected health information were compromised. The organization took systems offline, engaged forensic experts, notified law enforcement, and offered credit monitoring services.