New West Health Services
ent_163a25a4d2c303510d500496
Disclosures
4
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
28,209
nationwide · HHS OCR MT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- New West Health Services
- Normalized
- new west health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- newwestmedicare.com
Disclosure history (4)newest first
- Massachusetts State AGas victim2016-01-19
New West Health Services reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-01-19. 6 Massachusetts residents were affected. The report records the breach type as electronic.
- MONTANAHHS OCRas victim2016-01-15
New West Health Services d/b/a New West Medicare (Health Plan, MT) reported to HHS OCR on 2016-01-15 a Loss affecting 28,209 individuals. An employee's unencrypted laptop was stolen from a hotel meeting room. Breached ePHI included demographic info, SSNs, Medicare claim numbers, financial information, diagnoses, medical histories, and prescription data. The CE notified affected individuals and media, offered free credit monitoring, recalled and encrypted all laptops, added geo-location and remote-wipe capabilities, retrained staff, and sanctioned the involved employee. OCR obtained assurances of corrective action.
- Montana State AGas victim2016-01-15
New West Health Services d/b/a New West Medicare notified Montana and other state residents that a laptop containing customer PII, PHI, and financial data was stolen on Nov 18, 2015. No evidence of misuse was found. The company engaged forensic investigators, notified law enforcement, and offered credit monitoring.
- New Hampshire State AGas victim2016-01-15
New West Health Services d/b/a New West Medicare reported the theft of a company laptop on November 18, 2015, in Missoula, Montana. The unencrypted laptop contained personal and health information of five New Hampshire residents, including names, addresses, Social Security numbers, Medicare claim numbers, and for two individuals, medical history and diagnosis. The company notified the NH Attorney General and affected residents on January 15, 2016, and offered one year of credit monitoring.