FLMisuseHealthcareFinancial ServicesHealthcareKnowledge AbuseMisuse OtherBusiness Associate (HIPAA)Customer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumResolved
Florida Blue
bd_e5d93551d400a5f2 · schema v1 · pii pii-v1
Full breach record for Florida Blue →Florida Blue (FL Health Plan) reported to HHS on 2017-10-27 an Unauthorized Access/Disclosure affecting 939 individuals. Breached information was on Paper/Films. On August 30, 2017, employees of business associate Alliance & Associates Financial Services, Inc. impermissibly took PHI (names, DOBs, addresses, SSNs, medical history, banking/payment info) to a new employer. The CE recovered the PHI, provided credit monitoring, and OCR opened a separate review of the BA.
HIPAA clock✓ HHS notified8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed939 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 27, 2017
- Raw hash
- 31e3fcb49ed18033e67a1d3c4a2606a7669a433567a9f76e6f9022717dcea4f0
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Florida Bluenorm: florida blue
- Domain
- floridablue.com
- Industry
- Insurance — Health
Victim entity
- Name
- Florida Bluenorm: florida blue
- Domain
- floridablue.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Aug 30, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 939
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access· Alliance & Associates Financial Services, Inc.
- Threat actor
- Partner
- Regulator citations
- HHS OCR breach notification submittedOCR opened a separate review of the business associateOCR obtained assurances of corrective action implementation
- Third party
- via Alliance & Associates Financial Services, Inc.
- Initial access
- insider_action
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 30, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.