FLAccidentalHealthcareFinancial ServicesHealthcareMisdeliveryCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighResolved
WellCare Health Plans, Inc.
bd_b77149e91ac15d9a · schema v1 · pii pii-v1
Full breach record for WellCare Health Plans, Inc. →WellCare Health Plans, Inc. (FL) reported to HHS OCR on 2018-09-14 an Unauthorized Access/Disclosure affecting 26,942 individuals via Paper/Films. Between January 20 and June 20, 2018, appointment reminder letters were mistakenly mailed to wrong members, exposing name, age, Medicaid number, healthcare providers, and appointment reason. The CE terminated one staff member, retrained another, updated policies, and created an automated mailing procedure following OCR investigation.
HIPAA clockDiscovered Jul 25, 2018 → Notified Sep 14, 201851d ✓ HIPAA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed26,942 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 14, 2018
- Raw hash
- 50353b59e40024b0f0d6434950cf774dd1e16a6ce3442c23879ae86b8a6f643c
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- WellCare Health Plans, Inc.norm: wellcare health plans
- Domain
- wellcare.com
- Industry
- Insurance — Health
Victim entity
- Name
- WellCare Health Plans, Inc.norm: wellcare health plans
- Domain
- wellcare.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Jul 25, 2018
- Materiality determined
- —
- Notification sent
- Sep 14, 2018
- Affected individuals
- 26,942
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- HHS OCR investigation; OCR directed creation of new automated mail reminder procedure
- Initial access
- insider_action
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 51dHHS notified · 51d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jul 25, 2018→ Notified: Sep 14, 201851d 60 days HIPAA 60-day OK HIPAA Discovered: Jul 25, 2018→ Notified: Sep 14, 201851d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.