UCare Minnesota
bd_5f580a4a273da417 · schema v1 · pii pii-v1
Full breach record for UCare Minnesota →UCare Minnesota, a Minnesota-based health plan, reported to HHS on 2020-09-18 that numerous employees fell victim to an email phishing scheme affecting the ePHI of 4,806 individuals. Breached information (located in Email) included names, addresses, birthdates, claims and financial information, medications prescribed, diagnoses, and other treatment information. The CE notified HHS, affected individuals, and media, and implemented additional safeguards and a fraud claims review process. OCR provided technical assistance on Security Rule and Breach Notification Rule compliance.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 18, 2020
- Raw hash
- 7d5bf5d60f6d389a609efb63b26193c7cd4c237bfb57b850c6009bd13af95f62
Source filing
Reporting entity
- Name
- UCare Minnesotanorm: ucare minnesota
- Domain
- ucare-inreceivership.com
- Industry
- Insurance — Health
Victim entity
- Name
- UCare Minnesotanorm: ucare minnesota
- Domain
- ucare-inreceivership.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4,806
- Data types
- IDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- OCR provided technical assistance regarding Security Rule and Breach Notification Rule policies and procedures.
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.