Menu
Browse

Cyber Incident Victim: Healthplex Inc.

Date:

Nov 2021

Location:

United States of America

Summary

Healthplex Inc. experienced a phishing attack compromising an employee's email account, exposing personal and protected health information of 89,955 dental plan enrollees. The breached data included names combined with sensitive details such as Social Security numbers, financial information, medical treatment codes, and login credentials. Following an investigation, the organization secured the account, notified affected individuals, and offered identity theft protection services. The incident resulted in a $400,000 penalty from regulatory authorities for violations of data security laws, prompting enhancements to email security measures to mitigate future risks.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 24, 2021, Healthplex Inc., a major New York dental insurance provider, experienced a phishing attack that compromised an employee’s email account. The breach was promptly detected, and Healthplex secured the affected account to prevent further unauthorized access. An investigation was initiated to determine the scope and nature of the incident. On April 5, 2022, Healthplex confirmed the compromised email account contained personal and protected health information belonging to 89,955 individuals enrolled in its dental plans. The exposed data included first and last names combined with one or more of the following: addresses, group names and numbers, member ID numbers, plan affiliations, dates of birth, dates of service, provider names, ADA codes and descriptions, billed/paid amounts, prescription drug names, Social Security numbers, banking information, credit card numbers, member portal usernames and passwords, email addresses, phone numbers, and driver’s license numbers. The breach did not impact all individuals uniformly, with data exposure varying per person.

Cyber Incident Image

Healthplex mailed notification letters to affected individuals on April 15, 2022, offering complimentary identity theft protection services through LifeLock. The New York Attorney General’s Office investigated the incident, identifying violations of state data security and consumer protection laws. Healthplex settled the investigation by paying a $400,000 financial penalty. In response to the breach, Healthplex implemented enhanced security measures for its email environment to reduce the risk of similar incidents. No additional unauthorized access or data misuse was confirmed beyond the initial compromise period. The incident exclusively involved the single employee email account targeted in the November 2021 phishing attack, with no evidence of broader system infiltration.

Sources
Sources available to members
1 source