Signify Health, LLC
bd_0875ca5387cc3cfc · schema v1 · pii pii-v1
Full breach record for Signify Health, LLC →Signify Health, LLC, a healthcare business associate, discovered on October 12, 2020, that an employee had inappropriately published their login credentials for the Jira IT support ticketing system on a public job board. The credentials were revoked within three hours. Forensic investigation by Kroll found no evidence that the credentials were used to access, view, or exfiltrate protected health information (PHI). The potentially affected data included names, addresses, SSNs, and medical records. One New Hampshire resident was identified as affected. Signify terminated the employee, implemented two-factor authentication, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 12, 2020
Begins
Oct 12, 2020
Discovered
Mar 15, 2021
Filed
vs. sector median
+11 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Indiana State AGbd_0aee3c235ff55b2e2021-03-11 · +4dVerified
- Massachusetts State AGbd_dce5fc4cef1d46fe2021-03-11 · +4dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.