Managed Health Services
bd_16bfe8585b6e0bd6 · schema v1 · pii pii-v1
Full breach record for Managed Health Services →On March 13, 2016, Managed Health Services (IN, Health Plan) discovered that a CRM export file dated February 24, 2016 mismatched member addresses, causing New Member Packets and ID cards — containing names, Medicaid ID numbers, and PHI — to be mailed to incorrect recipients, including members of its Ohio sister plan. Approximately 610 individuals were affected. The CE corrected the export error, improved QA procedures, implemented new technical safeguards, notified HHS/media/affected individuals, and provided workforce training. OCR obtained documented assurances of corrective action. Breached information located on Paper/Films.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 1, 2016
- Raw hash
- 83fb3b631e1601ea63a8f19a2264792d86e00b09b606f1bb63dc81b3c8600afd
Source filing
Reporting entity
- Name
- Managed Health Servicesnorm: managed health
- Industry
- Insurance — Health
Victim entity
- Name
- Managed Health Servicesnorm: managed health
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Mar 13, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 610
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- Reported to Indiana state regulatorsBreach notification submitted to HHS OCROCR obtained documented assurances of corrective actions
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Mar 13, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.