Point32Health, the parent company of Harvard Pilgrim Health Care and Tufts Health Plan, recently suffered a cybersecurity ransomware incident that targeted systems used to serve members, accounts, brokers, and providers.
The company proactively took certain systems offline and notified law enforcement officials and regulators. The incident affected members covered by Harvard Pilgrim Health Care’s commercial and New Hampshire Medicare Stride plans, but the company has no reason to believe Tufts Health Plan products were affected. Point32Health is currently working with third-party cybersecurity experts to investigate the situation further and ensure the privacy and security of the data entrusted to them. If sensitive information is involved in the incident, the company will notify the individuals in accordance with applicable law.
Ransomware attacks involve criminals encrypting victims’ data and demanding ransom payments to unlock it. The FBI’s Boston Division warned organizations about the growing threat of cyberattacks last October, citing an 85% increase in ransomware infections reported to the Boston office in 2021 from the previous year.