Centene Management Corporation
bd_ea3dd49699c731f0 · schema v1 · pii pii-v1
Full breach record for Centene Management Corporation →An employee of business associate Centene Management Company downloaded data files containing PHI of 8,208 individuals to an unauthorized removable storage device before resigning. The employee returned a company-issued laptop on 2015-03-23, but it was not connected to the network for processing per standard procedure, delaying detection. On 2015-10-08, a data loss prevention tool discovered the impermissible downloads when the laptop was finally connected. PHI included names, addresses, dates of birth, medical ID numbers, and in some cases SSNs. Affected members were enrollees of covered entities Bridgeway Health Solutions and Superior Health Plan. The BA notified HHS, affected individuals, and media, and provided substitute notice. Remediation included new IT-equipment processing policy and DLP controls preventing downloads to unauthorized external storage. OCR provided technical assistance on Security Rule risk analysis/management.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 15, 2015
- Raw hash
- e88bb247e9f544e7b842a45600054c834d7391a40526ebbde2c3004a72861e46
Source filing
Reporting entity
- Name
- Centene Management Corporationnorm: centene management
- Industry
- Health Plan
Victim entity
- Name
- Centene Management Corporationnorm: centene management
- Industry
- Health Plan
- Industry
- Healthcaresource default
Incident
- Discovered
- Oct 8, 2015
- Materiality determined
- —
- Notification sent
- Oct 15, 2015
- Affected individuals
- 8,208
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Insider
- Threat actor
- Internal
- Regulator citations
- HHS OCR breach report filed 2015-10-15OCR provided technical assistance regarding Security Rule risk analysis and risk management
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 7dHHS notified · 7d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 8, 2015→ Notified: Oct 15, 20157d 60 days HIPAA 60-day OK HIPAA Discovered: Oct 8, 2015→ Notified: Oct 15, 20157d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.