Concordia Plan Services
bd_1e77ea07f4f8afcc · schema v1 · pii pii-v1
Full breach record for Concordia Plan Services →2 incidents on fileConcordia Plan Services on behalf of the Concordia Health Plan (MO, Health Plan) reported to HHS OCR on 2015-04-16 a Hacking/IT Incident affecting 12,500 individuals. Blue Cross and Blue Shield of Minnesota, a business associate, stored the covered entity's ePHI on servers belonging to its parent, Anthem, Inc. Anthem experienced a series of cyberattacks exposing ePHI of ~79 million people. Affected data included names, SSNs, medical IDs, addresses, dates of birth, email addresses, and employment information. HHS OCR's separate review of Anthem resulted in a monetary settlement and corrective action plan. Breached information located on Network Server.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Apr 16, 2015
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.