DisclosureLens
AccidentalHealthcareProfessional ServicesHealthcareMisconfigurationCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDHealth (basic)MediumResolved

Keenan & Associates

bd_412f5c0756271b19 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 9, 2015

Filed

Dec 1, 2015

To disclose

8 weeks

Affected

Not disclosed

Linked

3 filings

Confidence

65%
Full breach record for Keenan & Associates4 incidents on file

Keenan & Associates, a third-party health insurance administrator, discovered on October 9, 2015, that documents containing employee and dependent information (names, addresses, phone numbers, birth dates, plan identifiers, and some SSNs) were potentially searchable on the Internet due to a vendor's misconfiguration of security settings on a portal. The documents did not contain medical claims or diagnostic codes. Keenan reconfigured the portal, engaged Kroll for two years of identity monitoring, and instructed vendors to stop using the responsible software tool.

Incident timeline

discovery → filing · 8 weeks / 53 days

Oct 9, 2015

Begins

Oct 9, 2015

Discovered

Dec 1, 2015

Filed

vs. sector median

3 wks faster

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 2 states

View merged incident ↗
HHS OCRDec 1 · first
California State AGDec 1 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.