DAP Health, Inc.
ent_eb32c81528708b7610701d2e
Disclosures
4
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
129,048
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DAP Health, Inc.
- Normalized
- dap health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- California State AGas victim2024-12-26
DAP Health, Inc. detected suspicious activity in its email environment on July 22, 2024. An unauthorized actor accessed and acquired files and data stored within the email environment. The breach occurred on July 8, 2024. Affected data includes personal information of employees, patients, and clients, potentially including names, addresses, SSNs, and health information. DAP Health engaged third-party cybersecurity firms, conducted a forensic investigation, and is offering 12 months of credit monitoring and fraud assistance to affected individuals.
- Montana State AGas victim2024-12-26
DAP Health, Inc. notified Montana AG of a July 22, 2024 email compromise via phishing. Unauthorized actors accessed files containing PII (names, SSNs, DOBs, driver's licenses) of patients, employees, and clients. DAP Health engaged forensic investigators and offered 12 months of credit monitoring. Notification sent December 26, 2024.
- Illinois State AGas victim2024-12-01
DAP HEALTH filed a data-breach notice with the Illinois Attorney General in December 2024 (case 24-12-047). The register records the breach as discovered on July 22, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- CALIFORNIAHHS OCRas victim2024-09-24
DAP Health, Inc. (Healthcare Provider, CA) reported to HHS OCR on 2024-09-24 a Hacking/IT Incident — email phishing scheme — affecting 129,048 individuals. Employees were targeted by phishing emails, compromising PHI including demographic, clinical, and financial information located in email systems. The entity notified affected individuals, the media, and posted a substitute notice on its website. Additional administrative, technical, and security safeguards were implemented. OCR provided technical assistance.