National DCP Health Plan
bd_bb359e389c4f1a39 · schema v1 · pii pii-v1
Full breach record for National DCP Health Plan →In March 2017, an employee of National DCP Health Plan (GA, Health Plan) followed a link in a phishing email, resulting in an unauthorized external actor accessing her email account. PHI exposed for 1,190 individuals included health plan enrollment data: names, addresses, SSNs, and dates of birth. The CE notified HHS, affected individuals, and posted notice on its website; it also reported to the FBI and Secret Service. OCR investigated and obtained assurances that the CE implemented MFA for email, improved inbound email safeguards, and conducted phishing awareness training for its workforce. Breached information located on Email.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 1, 2017
Begins
Aug 8, 2017
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.