
Point32Health, the parent company of Harvard Pilgrim Health Care and a leading health insurance provider, said the sensitive personal information of its current and former customers were compromised as a result of a ransomware attack on its systems.On April 17th, Point32Health suffered a massive technical outage as a result of a ransomware attack. The company said the security incident affected systems used to service members, accounts, brokers, and providers. Point32Health’s official website was down for a while, and some customers who tried calling the insurer said they experienced technical difficulties.Point32Health said that after identifying the unauthorised activity, out of caution, it proactively took certain systems offline to contain the threat. While Point32’s website was operational the next day, Harvard Pilgrim’s website remained unavailable for some time.The insurer also confirmed that Tufts Health Plan, Tufts Medicare Preferred, Tufts Health Public Plans, and Care Partners of Connecticut systems weren’t affected by the ransomware attack and were accessible to customers.In a recent update, Harvard Pilgrim Health Care said that an investigation into the ransomware attack “identified signs that data was copied and taken from Harvard Pilgrim systems between March 28, 2023, and April 17, 2023.”“Harvard Pilgrim determined that the files at issue may contain personal information and/or protected health information belonging to current and former subscribers and dependents, and current contracted providers,” it said.It said the compromised information included names, physical addresses, phone numbers, dates of birth, health insurance account information, Social Security numbers, provider taxpayer identification numbers, and clinical information like medical history, diagnoses, treatment, dates of service, and provider names.While the insurance provider found no evidence of the compromised information being misused, the possibility of the same can’t be ruled out. The company has started notifying all affected individuals about the cyber security incident and sharing best practices to avoid cybercrimes including identity theft.Harvard Pilgrim is also offering two years of complimentary identity protection and credit monitoring services to all affected individuals and is advising them to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to proper law enforcement authorities, including the police and state attorney general.“In response to this incident, Harvard Pilgrim is taking steps to implement additional data security enhancements and safeguards to better protect against similar events in the future. Harvard Pilgrim is, and has always been, committed to prioritizing the security of the data entrusted to it,” the company added.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543