Hogan Services Inc. Health Care Premium Plan
bd_e790eabf81a9e264 · schema v1 · pii pii-v1
Full breach record for Hogan Services Inc. Health Care Premium Plan →On March 30, 2012, Hogan Services Inc. (HSI), sponsor of a fully insured employee health plan (MO), erroneously emailed ePHI of approximately 1,134 individuals to 287 employees. Exposed data included names, SSNs, dates of birth, gender, plan IDs, member IDs, enrollment dates, coverage types, and dependent relationship info. HSI shut down its email server, deleted ePHI from workstations, shredded printed copies, and notified HHS and affected individuals. Following OCR investigation, HSI ceased ePHI handling, retrained staff, and deployed encryption. Breached information located on Email.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 11, 2012
- Raw hash
- 787bdc7b2a8e1f9b22df28f381e99e204b716af52ca4c60fc630f6e90fd94aa9
Source filing
Reporting entity
- Name
- Hogan Services Inc. Health Care Premium Plannorm: hogan services inc health care premium plan
- Industry
- Insurance — Health
Victim entity
- Name
- Hogan Services Inc. Health Care Premium Plannorm: hogan services inc health care premium plan
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Mar 30, 2012
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,134
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- OCR investigation completed; OCR obtained assurances that HSI implemented corrective actions.
- Initial access
- insider_action
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Mar 30, 2012→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.