ConnectiCare
bd_c64a991ed42830ac · schema v1 · pii pii-v1
Full breach record for ConnectiCare →2 incidents on fileConnectiCare (CT, Health Plan) reported to HHS OCR on 2018-02-21 an Unauthorized Access/Disclosure affecting 1,834 individuals. On January 4, 2018, CE learned that its business associate RR Donnelly sent subscribers the wrong identification cards due to a programming logic error, exposing demographic and health plan information. OCR found CE policies and BA agreement compliant with the Privacy Rule. RR Donnelly implemented corrective coding logic on January 24, 2018. Individuals and media were notified per Breach Notification Rule. Breached information located on Paper/Films.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 4, 2018
Begins
Jan 4, 2018
Discovered
Feb 21, 2018
Filed
vs. sector median
5 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.