Keenan & Associates
bd_412f5c0756271b19 · schema v1 · pii pii-v1
Full breach record for Keenan & Associates →4 incidents on fileKeenan & Associates, a third-party health insurance administrator, discovered on October 9, 2015, that documents containing employee and dependent information (names, addresses, phone numbers, birth dates, plan identifiers, and some SSNs) were potentially searchable on the Internet due to a vendor's misconfiguration of security settings on a portal. The documents did not contain medical claims or diagnostic codes. Keenan reconfigured the portal, engaged Kroll for two years of identity monitoring, and instructed vendors to stop using the responsible software tool.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 9, 2015
Begins
Oct 9, 2015
Discovered
Dec 1, 2015
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- HHS OCRbd_01a0a9b2ade957462015-12-01Verified
- Massachusetts State AGbd_8c9f0daebe5177722015-12-02 · +1dVerified
Filing propagation · 3 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.