Healthplex

Mar 2023 · Graded Verified · Healthcare and Life Sciences · Government record

Incident summary

HealthplexMar 2023
$2M
Fines & legal costs
Regulatory / legal
Healthplex’s phishing incident exposed the personal and health information of approximately 89,955 people, including nearly 64,000 New York residents. The attacker gained access to an employee mailbox containing more than 100,000 emails accumulated over roughly 20 years, while the company lacked both an effective retention policy and required multifactor authentication. Healthplex ultimately paid $400,000 to the New York attorney general and another $2 million to the New York Department of Financial Services. This is a useful impact example because the consequences are established: tens of thousands of victims, years of unnecessary data retention and $2.4 million in regulatory penalties.
Attested: a published report credits an identifiable source for this figure.
Healthcare and Life Sciences
NYDFS cybersecurity enforcement action
Initial attack type phishing or social engineering confirmed · Impact data theft confirmed
Regulatory penalty
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
undated$2 millionAAttestedhipaajournal.com ↗
Corroborating records

About this record

This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete On the Government Record ledger ← Back to the index