PRPhysicalHealthcareFinancial ServicesHealthcareTheftFormer employee of Triple-S Advantage SolutionsBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedActor NamedDelayed DiscoveryHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighResolved
Triple-S Salud, Inc.
bd_41ede723f0211a91 · schema v1 · pii pii-v1
Full breach record for Triple-S Salud, Inc. →On March 27, 2014, Puerto Rico Health Insurance Administration reported to HHS a Theft affecting 46,473 individuals. A former employee of Triple-S Advantage Solutions (BA of Triple-S Salud) copied beneficiaries' ePHI—names, DOBs, contract numbers, HICN, home addresses, and SSNs—onto a CD before October 9, 2013, later downloading it at a new employer. Discovery occurred January 14, 2014. Breached info was on an Other Portable Electronic Device. OCR investigation led to risk analysis, policy revisions, and staff retraining commitments.
HIPAA clockDiscovered Jan 14, 2014 → Notified Mar 27, 201472d ✗ HIPAA 60-day late13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed46,473 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 15, 2014
- Raw hash
- f1af41c41c9e3fb44e50ec419a43571be36f55a723273f317af15fad6537e676
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Triple-S Salud, Inc.norm: triple s salud
- Domain
- salud.grupotriples.com
Victim entity
- Name
- Triple-S Salud, Inc.norm: triple s salud
- Domain
- salud.grupotriples.com
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Jan 14, 2014
- Materiality determined
- —
- Notification sent
- Mar 27, 2014
- Affected individuals
- 46,473
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access· former employee of Triple-S Advantage Solutions
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Former employee of Triple-S Advantage SolutionsInternal
- Regulator citations
- OCR investigation conducted; covered entity committed to risk analysis, risk management plan, policy revisions, and staff retraining
- Third party
- via Triple-S Advantage Solutionsbusiness associate
- Initial access
- insider_action
Compliance
- Time to disclose
- 13 weeks(91 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 72dHHS notified · 72d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 14, 2014→ Notified: Mar 27, 201472d 60 days HIPAA 60-day late HIPAA Discovered: Jan 14, 2014→ Notified: Mar 27, 201472d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.