National DCP Health Plan
bd_bb359e389c4f1a39 · schema v1 · pii pii-v1
Full breach record for National DCP Health Plan →In March 2017, an employee of National DCP Health Plan (GA, Health Plan) followed a link in a phishing email, resulting in an unauthorized external actor accessing her email account. PHI exposed for 1,190 individuals included health plan enrollment data: names, addresses, SSNs, and dates of birth. The CE notified HHS, affected individuals, and posted notice on its website; it also reported to the FBI and Secret Service. OCR investigated and obtained assurances that the CE implemented MFA for email, improved inbound email safeguards, and conducted phishing awareness training for its workforce. Breached information located on Email.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 8, 2017
- Raw hash
- d171b353b8f34b4f4752c158d2ebf466291117282ea20fff6daeb1e3e3b6c6ec
Source filing
Reporting entity
- Name
- National DCP Health Plannorm: national dcp health plan
- Industry
- Insurance — Health
Victim entity
- Name
- National DCP Health Plannorm: national dcp health plan
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,190
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported to HHS OCRReported to FBIReported to Secret ServiceOCR investigation conducted; corrective actions implemented with OCR assurances obtained
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.