FLAccidentalHealthcareHealthcareMisdeliveryBusiness Associate (HIPAA)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMediumContained
WellCare Health Plans, Inc.
bd_160bd3331958e862 · schema v1 · pii pii-v1
Full breach record for WellCare Health Plans, Inc. →WellCare Health Plans, Inc. reported to HHS on 2017-08-11 a Unauthorized Access/Disclosure affecting 1214 individuals. Breached information located on Paper/Films. A business associate, O’Neil Printing, Inc., accidentally sent mislabeled envelopes containing insurance membership identification cards to incorrect addresses between July 13 and July 17, 2017. The mistake was discovered on July 20, 2017.
HIPAA clock✓ HHS notified22 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,214 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 11, 2017
- Raw hash
- 2a4dbce98e1dfc204f000f8f2e282dcd97298cc897ee6cf0a601104ddb09ad96
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- WellCare Health Plans, Inc.norm: wellcare health plans
- Industry
- Insurance — Health
Victim entity
- Name
- WellCare Health Plans, Inc.norm: wellcare health plans
- Industry
- Insurance — Health
- Industry
- Healthcaresource default
Incident
- Discovered
- Jul 20, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,214
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1530 Data from Cloud Storage Object
- Threat actor
- Internal
- Regulator citations
- Notified HHSOCR obtained assurances that the CE implemented the corrective actions listed above
- Third party
- via O’Neil Printing, Inc.business associate
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jul 20, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.