FEDERALAccidentalHealthcareHealthcarePublishing ErrorSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICMediumResolved
Insulet Corporation
bd_ebaf86a6a4d9eab2 · schema v1 · pii pii-v1
Full breach record for Insulet Corporation →On August 18, 2017, Insulet Corporation reported a data breach involving its business associate, Brainshark Inc. A technical error led to the exposure of 3,732 customer email addresses to other customers. In response, the training module causing the error was deactivated, Brainshark disabled the site, and the incident was investigated. Insulet Corporation provided breach notifications to the Department of Health and Human Services (HHS) and the 1,469 affected individuals. As a corrective action, the company terminated its contract with Brainshark Inc.
HIPAA clock✓ HHS notified9 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,469 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 17, 2017
- Raw hash
- e89288c8a563952013e99246716ac7283124029057dbd9946ce4c810065828cd
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Insulet Corporationnorm: insulet
- Domain
- insulet.com
Victim entity
- Name
- Insulet Corporationnorm: insulet
- Domain
- insulet.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Aug 18, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,469
- Data types
- IDENTITY_BASIC
- Attack vector
- Unknown
- Regulator citations
- Provided breach notification to HHSOCR obtained assurances that the CE implemented the corrective actions
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 18, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.