Keystone Insurance Services
bd_578914c1eba6c106 · schema v1 · pii pii-v1
Full breach record for Keystone Insurance Services →KEYSTONE INSURERS GROUP reported to HHS on 2014-05-06 a breach involving the improper disclosure of Protected Health Information (PHI) via email. The incident, classified as 'Other' (Improper Disposal/Disclosure), affected 1008 individuals. The breach occurred between January 23, 2013, and March 3, 2013, when the Business Associate disclosed more than the minimum necessary information to healthcare providers. Affected data included demographic information (names, addresses, birthdates, insurance numbers) and clinical information (diagnoses, treatments, prescriptions, expenses). The Covered Entity, City of Henderson, terminated the agreement with the BA, obtained certificates of deletion, and implemented new privacy policies and training.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 6, 2014
- Raw hash
- ba55e86ecb1136d21e6131ccd2253ce88fe6fe347efd56c9e21c0264b06ec623
Source filing
Reporting entity
- Name
- Keystone Insurance Servicesnorm: keystone insurance
- Domain
- keystoneinsurance.com
- Industry
- Business Associate
Victim entity
- Name
- Keystone Insurance Servicesnorm: keystone insurance
- Domain
- keystoneinsurance.com
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,008
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unknown
- Threat actor
- Internal
- Regulator citations
- Provided breach notification to HHS
- Third party
- via City of Hendersoncovered entity
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.