HealthPartners Inc
bd_4272d4332d605766 · schema v1 · pii pii-v1
Full breach record for HealthPartners Inc →HealthPartners Inc (MN, Health Plan) reported to HHS on 2014-03-21 an Unauthorized Access/Disclosure affecting 27,839 individuals. On January 21, 2014, an employee's husband accessed devices containing PHI while assisting her with telework tasks — formatting data and creating spreadsheet reports — thereby impermissibly receiving demographic and clinical information of 37,606 individuals (broader internal count). Breached information was located on Desktop Computer, Laptop, and Other Portable Electronic Device. HealthPartners implemented corrective measures including updated policies, employee training, encryption, removable-media controls, and network access restrictions. OCR obtained documented assurances of compliance.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 21, 2014
- Raw hash
- 9650bfee4cbc086996fcb735df7106312db9c519d875fa17770655cebc4b7fa8
Source filing
Reporting entity
- Name
- HealthPartners Incnorm: healthpartners
- Domain
- healthpartners.com
- Industry
- Insurance — Health
Victim entity
- Name
- HealthPartners Incnorm: healthpartners
- Domain
- healthpartners.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Jan 21, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 27,839
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- HHS OCR — corrective action plan accepted; OCR obtained documented assurances of implementation
- Initial access
- insider_action
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 21, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.