CarePlus Health Plans [case 18772]
bd_1ad5355df5e3916d · schema v1 · pii pii-v1
Full breach record for CarePlus Health Plans [case 18772] →CarePlus Health Plans (KY) reported to HHS OCR on 2015-10-06 an unauthorized access/disclosure affecting 2,873 individuals. On September 11, 2015, 'Late Enrollment Penalty Premium Statements' were mailed to incorrect members after a printing apparatus was accidentally programmed to insert two statements per envelope instead of one. PHI exposed included names, addresses, and identification numbers. Breached information was on paper/films. The CE mailed correct statements, sanctioned the responsible employee, and retrained staff. OCR obtained assurances of corrective actions.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 6, 2015
- Raw hash
- d3c2b5d4767c026766aa3d9cab0b24128c98a34c75edd2b05347166c4ab117f0
Source filing
Reporting entity
- Name
- CarePlus Health Plans [case 18772]norm: careplus health plans case 18772
- Industry
- Insurance — Health
Victim entity
- Name
- CarePlus Health Plans [case 18772]norm: careplus health plans case 18772
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Sep 18, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,873
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- HHS OCR breach notification filedOCR obtained assurances of corrective actions
- Initial access
- insider_action
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Sep 18, 2015→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.