FEDERALMalwareHealthcareHealthcareRansomwareBusiness Associate (HIPAA)Customer Data InvolvedData EncryptedRansom DemandedHEALTH_BASICIDENTITY_BASICMedium
Community Health Plan of Washington
bd_e74e7ea642691fa1 · schema v1 · pii pii-v1
Full breach record for Community Health Plan of Washington →Community Health Plan of Washington reported to HHS on 2017-01-03 a ransomware incident at a business associate, Summit Reinsurance, affecting 1,375 individuals. The breach, discovered on November 3, 2016, occurred on a network server and compromised protected health information including names, addresses, dates of birth, provider names, and health insurance claim information.
HIPAA clock✓ HHS notified9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_8eedda41b0dc7189Montana State AGfiled 2016-12-29(5d gap)Candidate
- bd_0a35fce30888272bWashington State AGfiled 2016-12-21(13d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 3, 2017
- Raw hash
- 3590f5a0cea549dc029ba517414bf737f28b3d065235de62c8dff53b6bf4c298
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Community Health Plan of Washingtonnorm: community health plan of washington
- Industry
- Insurance — Health
Victim entity
- Name
- Community Health Plan of Washingtonnorm: community health plan of washington
- Industry
- Insurance — Health
- Industry
- Healthcaresource default
Incident
- Discovered
- Nov 3, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,375
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- PartnerFinancial
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Nov 3, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.