SAG-AFTRA Health Plan reported to HHS on 2024-12-02 a Hacking/IT Incident affecting 98,474 individuals. Breached information located on Email. An employee was targeted by an email phishing scheme, exposing names, SSNs, and claims information. The entity implemented additional safeguards and retrained staff.
Affected (this filing): 98,474
Most recent
3 State AG filingsDec 2, 2024ExpandCollapse
NHMTCA
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
SAG-AFTRA Health Plan notified the New Hampshire Attorney General of a security incident where an employee's email account was compromised via phishing between Sept 17-18, 2024. The breach exposed personal and health information of 38 NH residents. The Plan contained the incident, engaged third-party experts, notified law enforcement, and offered credit monitoring services.
Affected (this filing): 38
🦬Montana State AGlinked via same-victim cross-source · 100%
SAG-AFTRA Health Plan reported a data breach to the Montana Attorney General. The breach was reported on 2024-12-02. The breach occurred from 09/17/2024 to 03/18/2025. 60 Montana residents were affected.
Affected (this filing): 60
🐻California State AGlinked via multistate filing link · 100%
SAG-AFTRA Health Plan experienced a data breach after an employee's email account was compromised via a phishing email. Unauthorized access occurred between September 17 and 18, 2024. The incident exposed personal information including names, Social Security numbers, and potentially health insurance claims data for some plan participants. The Plan contained the incident, engaged third-party experts, notified law enforcement, and is offering one year of identity theft protection to affected individuals.