DisclosureLens
MISSOURIAccidentalHealthcareFinancial ServicesHealthcareMisdeliveryCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDHealth (basic)HighResolved

Hogan Services Inc. Health Care Premium Plan

bd_e790eabf81a9e264 · schema v1 · pii pii-v1

Severity

High

Discovered

Mar 30, 2012

Filed

May 11, 2012

To disclose

6 weeks

Affected

1,134

Confidence

97%
Full breach record for Hogan Services Inc. Health Care Premium Plan

On March 30, 2012, Hogan Services Inc. (HSI), sponsor of a fully insured employee health plan (MO), erroneously emailed ePHI of approximately 1,134 individuals to 287 employees. Exposed data included names, SSNs, dates of birth, gender, plan IDs, member IDs, enrollment dates, coverage types, and dependent relationship info. HSI shut down its email server, deleted ePHI from workstations, shredded printed copies, and notified HHS and affected individuals. Following OCR investigation, HSI ceased ePHI handling, retrained staff, and deployed encryption. Breached information located on Email.

HIPAA clock HHS report on time6 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 6 weeks / 42 days

Mar 30, 2012

Begins

Mar 30, 2012

Discovered

May 11, 2012

Filed

vs. sector median

6 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,134 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.