Confirmed breach. Intrusion Jul 31, 2023–Jun 27, 2024, discovered Apr 2, 2024 — the first regulatory filing landed 87 days later (flagged late). 1,000,000 individuals reported across the linked filings.
Mass General Brigham Health Plan, Inc. reported a ransomware attack on June 27, 2024, affecting approximately 1 million individuals. The incident involved data encryption and exfiltration. PHI, names, and government IDs were compromised. The company engaged forensic investigators and notified law enforcement.
Affected (this filing): 1,000,000
🏛️MASSACHUSETTSHHS OCRlinked via same-victim cross-source · 100%
Mass General Brigham Health Plan reported to HHS on 2024-06-28 a Unauthorized Access/Disclosure affecting 3,659 individuals. Breached information located on Other. An employee impermissibly shared system credentials with an unauthorized individual, exposing PHI including names, addresses, SSNs, and medical data. The CE provided credit monitoring, established a call center, sanctioned the employee, and retrained staff.
Mass General Brigham Health Plan notified consumers of an insider incident where an employee allowed an unauthorized person to access member data between July 2023 and April 2024. Data included names, SSNs, DOBs, and PHI. The employee was terminated, and 24 months of credit monitoring were offered.
VT AG >45 bday
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.