RSC Insurance Brokerage, Inc.
bd_fe0100e3a4b7fbac · schema v1 · pii pii-v1
Full breach record for RSC Insurance Brokerage, Inc. →RSC Insurance Brokerage, Inc. (MA), a business associate, reported to HHS on 2019-03-01 a Theft affecting 2,088 individuals (19,893 per description). A BA workforce member's backpack containing an unencrypted laptop was stolen. PHI involved included demographic, clinical, and health claims information. The BA notified nine covered entities, affected individuals, media, and HHS. Post-breach remediation included encrypted laptop replacement, device-wide encryption confirmation, policy revisions, and cybersecurity retraining. OCR provided technical assistance on notification timing.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_74f496ed77915c14Oregon State AGfiled 2019-03-01Verified
- bd_dd877224ae982562Montana State AGfiled 2019-03-01Verified
- bd_7fe23bd39baf57cfCalifornia State AGfiled 2019-03-06(5d gap)Verified
- bd_82bcb10591e7a1b3California State AGfiled 2019-04-03(33d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 1, 2019
- Raw hash
- 5a1c9ce3d93be62a42195fe34724d0d69c4831068a368761d316d0da8739fa1e
Source filing
Reporting entity
- Name
- RSC Insurance Brokerage, Inc.norm: rsc insurance brokerage
- Industry
- Business Associate
Victim entity
- Name
- RSC Insurance Brokerage, Inc.norm: rsc insurance brokerage
- Industry
- Business Associate
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,088
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- OCR provided technical assistance to the BA concerning the timing of its breach notificationsBA agreed to revise its policies and procedures in response to OCR guidance
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.