AccidentalMisconfigurationCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumResolved
Keenan & Associates
bd_412f5c0756271b19 · schema v1 · pii pii-v1
Full breach record for Keenan & Associates →Keenan & Associates, a third-party health insurance administrator, discovered on October 9, 2015, that documents containing employee and dependent information (names, addresses, phone numbers, birth dates, plan identifiers, and some SSNs) were potentially searchable on the Internet due to a vendor's misconfiguration of security settings on a portal. The documents did not contain medical claims or diagnostic codes. Keenan reconfigured the portal, engaged Kroll for two years of identity monitoring, and instructed vendors to stop using the responsible software tool.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_01a0a9b2ade95746HHS OCRfiled 2015-12-01Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-59125
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 1, 2015
- Raw hash
- ded89485c52bd7c06342abf8b85face0b4962f5b1afd8e94a64ec9ddf32ff3f6
Reporting entity
- Name
- Keenan & Associatesnorm: keenan associates
Victim entity
- Name
- Keenan & Associatesnorm: keenan associates
Incident
- Discovered
- Oct 9, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Misconfiguration
- Third party
- via Vendor
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.