Alegeus, a Waltham, Massachusetts benefits administration company, has disclosed a data breach that exposed Social Security numbers. A notice filed with Massachusetts regulators says the incident may have affected the privacy of some individuals’ personal health information.
Alegeus’s Data Breach Investigation
Alegeus is a benefits administration technology company based in Waltham, Massachusetts. It builds the platforms that sit behind the benefit accounts and payment tools offered by health plans, third-party administrators, human capital management providers and financial services firms. Because its technology runs under the brand of each partner, many people who are affected by an Alegeus incident may never have realized the company held their information at all.
The breach was reported to the Massachusetts Office of Consumer Affairs and Business Regulation. The filing refers to Health Plans Inc., known as HPI, as a partner taking part in the process of notifying consumers. The notice letter tells recipients that the incident may have affected the privacy of some of their personal health information, and the types of information confirmed as exposed include Social Security numbers.
What the public record does not yet say is just as important. The sample notice letter that accompanied the filing is a blank template: the sections describing what happened and what information was involved still contain unfilled placeholders instead of real details. As a result, the cause of the incident, the way an unauthorized party gained access, the date the problem began, the date it was discovered and the number of people affected have not been made public. This page does not guess at any of them.
The letter says Alegeus has taken steps to help protect the information of affected individuals and to better prevent similar incidents in the future, but the version of the notice available to the public does not describe what those steps were. The company also apologized for any concern or inconvenience the incident may cause and said it remains committed to safeguarding the privacy and security of personal information.
Health Plans Inc. is offering affected individuals two years of complimentary credit monitoring and identity protection through IDX. Recipients enroll by visiting the IDX website and entering the unique enrollment code printed in their own letter. Each code carries an expiration date that is listed in the notice, so anyone who receives a letter should enroll before that date passes. After enrolling, the credit monitoring feature has to be activated separately, otherwise it does not take effect. The company says that anyone who finds suspicious items on a credit report after enrolling can notify IDX by phone or through its website, and that a person who becomes a victim of identity theft because of this incident will be assigned a dedicated ID Care Specialist to help identify, stop and reverse the damage.
A dedicated customer service line has also been set up for questions about the incident, and the telephone number is printed in each notification letter. People who are unsure whether they are affected should look for a letter from Alegeus or from one of the health plans or administrators they deal with, since the company’s white-label model means the notice may arrive under a different name.
Companies that administer health savings, reimbursement and other benefit accounts handle a concentrated set of sensitive data. Enrollment and account records typically link a person’s name to a Social Security number, a home address and details about their health coverage. That is a general observation about the sector, not a finding about what happened at Alegeus, but it explains why vendors in this part of the benefits industry draw attention from criminals and from regulators.
A Social Security number is difficult to change and is the core of most identity checks. When it is exposed together with a name and personal health information, criminals can attempt to open credit accounts, file false tax returns, seek medical services or benefits in another person’s name, or build convincing phishing messages that reference real coverage details. The risk does not expire quickly, which is why free monitoring, credit report reviews and a fraud alert or freeze are all sensible steps for anyone who receives a notice.
If you receive a letter connected to this incident, keep it, read it closely and note the enrollment deadline. Be wary of unexpected calls, texts or emails that claim to be about the breach, and confirm any request through a phone number or website you already trust. As Alegeus, its partners or regulators release more information about what happened and how many people were affected, this page can be updated.
When Did This Breach Occur?
Alegeus has not publicly stated when the incident happened or when it was discovered, and the sample notice filed with Massachusetts regulators leaves its description of the incident blank. The filing was made through the Massachusetts Office of Consumer Affairs and Business Regulation. Check the date on any letter you receive, since that is the best indicator of when you were notified.
What Information Was Breached?
The notice says the incident may have affected the privacy of some personal health information, and the types of information confirmed as exposed include Social Security numbers. The sample letter does not fill in the full list of data elements, so other categories have not been confirmed. Your own letter should list what applies to you.
What You Can Do
If you receive a notice connected to Alegeus, consider these steps:
- Read the notice carefully, keep a copy for your records and note the expiration date on your IDX enrollment code.
- Enroll in the complimentary IDX credit monitoring and identity protection offered through Health Plans Inc., then activate the credit monitoring so it takes effect.
- Check your credit reports for free at annualcreditreport.com, and consider a fraud alert or credit freeze with Equifax, Experian and TransUnion.
- Review your benefit account statements, explanation of benefits forms and bank activity for anything you do not recognize.
- Be cautious with unexpected calls, texts or emails about the breach, and report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.
File a Data Breach Lawsuit Against Alegeus
If you received a notice that your Social Security number or personal health information was exposed in the Alegeus breach, you may have legal options. Companies that hold sensitive benefits and health-related records are expected to protect them, and a lawsuit can help hold them accountable when they fail to do so.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.