Required substitute notice
Member hotline phone number: (866) 676-3916
December 6, 2023
Orrick is notifying HAP members of an incident that may have exposed personal and protected health information of some members.
Re: Notice of data breach
HAP takes the responsibility to protect the information of its plan participants very seriously. A security incident affecting certain of HAP’s current or former participants occurred at a downstream vendor, as explained more fully below. Please be assured this incident did not involve HAP’s network or systems in any way. Because HAP has a direct relationship with you, however, HAP is posting this notice.
MultiPlan, Inc. (“MultiPlan”) provides services to your HAP health insurance plan. MultiPlan has been represented by the law firm Orrick, Herrington & Sutcliffe, LLP (“Orrick”) in certain matters, and, as part of that representation, Orrick received personal information about HAP plan participants. On March 13, 2023, Orrick detected that an unauthorized third party gained remote access to a portion of Orrick’s network, including a file share that Orrick used to store certain client files.
Upon detection, Orrick took immediate steps to block the unauthorized access and an investigation of the incident was launched with the support of leading outside cybersecurity experts. Orrick also notified law enforcement. On March 10, the unauthorized third party obtained files containing personal information.
The information affected may have included: full name, address, email, date of birth, healthcare provider, medical record number, claims information (date, cost of services, and claims identifiers), health insurance ID, and Social Security numbers.
Orrick mailed letters to individuals with impacted personal information on November 29, 2023. Orrick is offering these individuals two years of complimentary identity monitoring services, including credit monitoring and identity theft protection services. In addition to these actions, Orrick deployed additional security measures and tools with the guidance of third-party experts to strengthen the ongoing security of its network.
Orrick is not aware of any misuse of plan participant information. No financial information, such as financial account information or credit card numbers, was involved in this incident. It is always a good practice to remain vigilant and regularly review financial statements, credit reports, and Explanations of Benefits (EOBs) from health insurers for any unauthorized activity. This is a best practice for all individuals. If you identify suspicious activity, you should contact the company that maintains the account on your behalf.
Orrick has established a dedicated call center to answer questions. If you have any questions about this this incident or the services available to you, please call (866) 676-3916 Monday through Friday from 9:00am to 6:30pm Eastern time.