Newkirk Products, Inc.
bd_6e817458e194b87f · schema v1 · pii pii-v1
Full breach record for Newkirk Products, Inc. →Newkirk Products, Inc. (NY), a business associate issuing member healthcare ID cards, reported to HHS OCR on 2016-08-09 a Hacking/IT Incident affecting 3,466,120 individuals. Prior to its acquisition by a new parent company, unauthorized individuals accessed a network server containing ePHI of ~3.99M health plan members. Exposed data included names, addresses, plan/group/member IDs, dependent names, primary care provider, and in some cases Medicaid IDs, dates of birth, and premium invoice information. The former parent decommissioned the server; a new IT environment was established. OCR required a risk analysis, remediation plan, and updated HIPAA policies.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Aug 9, 2016
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Oregon State AGbd_9c9bb64f0ded79432016-08-17 · +8dVerified
- California State AGbd_b094e5550c9b1eba2016-08-18 · +9dVerified
- Montana State AGbd_376623410f8103262016-08-19 · +10dVerified
- California State AGbd_b27aaea900f941582016-08-19 · +10dVerified
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Aug 9 (NY), last Aug 19 (CA) — a 10-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.