FEDERALMisuseHealthcareHealthcarePrivilege AbuseCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICLowResolved
Contra Costa Health Plan
bd_7fcfe093a83931b6 · schema v1 · pii pii-v1
Full breach record for Contra Costa Health Plan →Contra Costa Health Plan reported to HHS on 2018-12-13 an incident of unauthorized access affecting 862 individuals. The breach occurred when a business associate, who had provided services under a false identity, accessed health plan enrollees’ protected health information (PHI), including demographic and clinical data. The breached information was located on the entity's Electronic Medical Record and Email systems. The incident was discovered on May 22, 2018.
HIPAA clock✓ HHS notified29 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b0f6a059b6d3fbb1California State AGfiled 2018-12-13Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 13, 2018
- Raw hash
- a245a2d3a3ed6b3e71dc9d0217ef526b3838d440265e8d159bb6d4ae9a7cba29
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Contra Costa Health Plannorm: contra costa health plan
- Industry
- Insurance — Health
Victim entity
- Name
- Contra Costa Health Plannorm: contra costa health plan
- Industry
- Insurance — Health
- Industry
- Healthcaresource default
Incident
- Discovered
- May 22, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 862
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
Compliance
- Time to disclose
- 29 weeks(205 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: May 22, 2018→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.