
Harvard Pilgrim Health Care, a Massachusetts-based and Point32Health-owned healthcare company, said the cyber security incident it experienced in 2022 compromised 2.64 million more individuals than initially believed.
In May last year, Point32Health, the parent company of Harvard Pilgrim Health Care and a leading health insurance provider, said it suffered a major technical outage as a result of a ransomware attack on April 17th.
The company said the security incident affected systems used to service members, accounts, brokers, and providers. Point32Health’s official website was down for a while and some customers who tried calling the insurer said they experienced technical difficulties.
While Point32’s website was operational the next day, Harvard Pilgrim’s website remained unavailable for some time. In a separate update, Harvard Pilgrim Health Care later said that an investigation into the ransomware attack “identified signs that data was copied and taken from Harvard Pilgrim systems between March 28, 2023, and April 17, 2023”.
It said the compromised information included names, physical addresses, phone numbers, dates of birth, health insurance account information, Social Security numbers, taxpayer identification numbers, and clinical information like medical history, diagnoses, treatment, dates of service, and provider names.
In filings with the U.S. Department of Health and Human Services and the Office of the Maine Attorney General, Harvard Pilgrim Health Care confirmed that at least 2,550,922 people were affected by the cyber security incident. The company also said that the ransomware attack affected certain systems that support the Harvard Pilgrim Health Care commercial and Medicare Advantage Stride plans.
In a recent filing with the Maine state regulator, Harvard Pilgrim Health Care said that it has identified another 2,632,275 individuals who were affected by the data security incident. In total, the cyber security incident compromised the sensitive personal information of at least 5,183,197 individuals.
While the insurance provider found no evidence of the compromised information being misused, the possibility of the same cannot be ruled out. Harvard Pilgrim has offered two years of complimentary identity protection and credit monitoring services to all affected individuals and is advising them to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and state attorney general.
“Point32Health has communicated to our provider partners that they should continue providing care to Harvard Pilgrim Health Care members during this ongoing incident and services will be covered,” the company added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543