Blue Cross and Blue Shield of Kansas City
bd_f88858558f781e7b · schema v1 · pii pii-v1
Full breach record for Blue Cross and Blue Shield of Kansas City →In February 2014, an internal employee of Blue Cross and Blue Shield of Kansas City (Health Plan, MO) exploited access to payment-by-phone systems to steal credit card information from 2,546 members making premium payments. Two members reported unauthorized charges, prompting investigation. The employee had a prior felony identity theft conviction missed due to an inaccurate background check by contractor Verifications Inc. The CE terminated the employee, replaced the background check vendor, notified HHS, individuals, and media, and reported to the FBI and local law enforcement. OCR confirmed corrective actions. Location of breached information: Other.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 11, 2014
- Raw hash
- a0312277c97fa8a2518e698411341c0b4c3d5dde46ab27519fd532410f0f9949
Source filing
Reporting entity
- Name
- Blue Cross and Blue Shield of Kansas Citynorm: blue cross and blue shield of kansas city
- Industry
- Insurance — Health
Victim entity
- Name
- Blue Cross and Blue Shield of Kansas Citynorm: blue cross and blue shield of kansas city
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Feb 1, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,546
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- InternalFinancial
- Regulator citations
- Notified HHS OCRReported to FBIReported to local law enforcement
- Initial access
- insider_action
Compliance
- Time to disclose
- 10 weeks(69 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Feb 1, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.