EHP takes the protection and proper use of plan member information very seriously. Regrettably, this notice concerns a cybersecurity incident that involved some of that information, and explains the circumstances of the incident, the measures we are taking in response, and offers steps patients may consider taking.
On June 22, 2023, EHP was notified that one of its vendors discovered a security incident on June 21, 2023. The vendor immediately initiated an investigation that confirmed that multiple downloads of information had been made by an unauthorized party between May 30, 2023 and June 2, 2023.
What Information Was Involved?
We conducted a comprehensive review of the information downloaded, which determined that that some plan members’ information was included. The information involved varied by individual but may have included one of more of the following: name, date of birth, address, email address, phone number, Social Security number, bank account information, and health insurance information.
What We Are Doing
We are working closely with the vendor to ensure systems are updated to block these activities and prevent disclosures of this nature from occurring in the future. EHP is committed to maintaining the privacy and security of your information and is taking this incident very seriously. Our vendor has notified law enforcement to mitigate this situation as best as possible.
Beginning on August 3, 2023, EHP is mailing letters to plan members whose information was identified through our review and for whom we have sufficient contact information. The letters include additional information on steps individuals can take to monitor and protect their personal information, as well as instructions for enrolling in complimentary credit monitoring and resolution services through IDX’s MyIDCareTM Identity Protection. Members who believe their information was involved but do not receive a letter by August 28, 2023 can contact IDX at (888) 703-9247 on weekdays between the hours of 9 am and 9 pm ET.
What You Can Do
As a precaution, we recommend members monitor their accounts and watch for any suspicious activity. If you suspect or discover that your information has been used inappropriately, please notify your local law enforcement or consumer protection agency.
We regret that this incident occurred as EHP takes the confidentiality of its members’ data very seriously. We have no reason to believe that anyone has misused this information.
For More Information
If you have any additional questions, please do not hesitate to visit IDX’s website at https://response.idx.us/notice-info or contact IDX at (888) 703-9247 on weekdays between the hours of 9 am and 9 pm ET.