Willis North America Inc. Medical Expense Benefit Plan
bd_ee1b0a75f296a2f0 · schema v1 · pii pii-v1
Full breach record for Willis North America Inc. Medical Expense Benefit Plan →Willis North America Inc. Medical Expense Benefit Plan (NY, Health Plan) reported to HHS on 2014-04-24 an Unauthorized Access/Disclosure affecting 4,830 individuals. A group health plan administrator accidentally emailed 1,889 plan participants a spreadsheet containing PHI of 4,830 participants, including names, dates of birth, and Social Security numbers. Breached information located in Email. No business associate was involved. The CE took extensive corrective action including deleting the email from inboxes, sanctioning the administrator, updating HIPAA training, and offering two years of identity theft protection.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 24, 2014
- Raw hash
- ff2b740b4e07c70c15fa672ed295bde4cb7c9a1c8369c60afa5f39b35890e6f8
Source filing
Reporting entity
- Name
- Willis North America Inc. Medical Expense Benefit Plannorm: willis north america inc medical expense benefit plan
- Industry
- Insurance — Health
Victim entity
- Name
- Willis North America Inc. Medical Expense Benefit Plannorm: willis north america inc medical expense benefit plan
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4,830
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- HHS OCR notified; OCR obtained assurances CE implemented corrective actions; CE expected to conduct risk analysis and implement remediation plan per Security Rule; CE to revise plan documents to comply with Privacy Rule.
- Initial access
- insider_action
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.