StayWell Health Management, LLC
ent_2e9fbab57035b6017cac9c0b
Disclosures
5
HHS OCR · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
19,474
nationwide · HHS OCR MN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- StayWell Health Management, LLC
- Normalized
- staywell health management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- FEDERALHHS OCRas victim2014-07-31
StayWell Health Management, LLC reported to HHS on 2014-07-31 a Hacking/IT Incident affecting 4487 individuals. Breached information located on Network Server.
- MNHHS OCRas victim2014-03-18
StayWell Health Management LLC (Business Associate, MN) was reported to HHS on 2014-03-18 for an Unauthorized Access/Disclosure affecting 1,746 individuals. The BA disclosed PHI on the internet, including names, email addresses, unique StayWell identification numbers, and wellness program participation data. The covered entity QBE Holdings, Inc. filed the report. OCR investigated and obtained assurances that corrective actions — including risk assessment, updated policies, and employee training — were implemented. Breached information was located on a Network Server.
- MNHHS OCRas victim2014-02-25
StayWell Health Management, LLC reported to HHS on 2014-02-25 a Unauthorized Access/Disclosure affecting 1511 individuals. Breached information located on Network Server.
- MNHHS OCRas victim2014-02-21
StayWell Health Management, LLC, a business associate of Missouri Consolidated Health Care Plan, reported to HHS on 2014-02-21 an Unauthorized Access/Disclosure affecting 10,024 individuals. On that date, the BA erroneously made a spreadsheet accessible via an internet link. The spreadsheet contained participants' names, email addresses, internal IDs, wellness program status, email notification info, and survey completion data. Breached information was located on a Network Server. The BA removed the spreadsheet, implemented a legacy system for ePHI in transit, and the CE updated its Privacy and Security Policy with encryption standards. OCR obtained documented assurances of corrective actions.
- MNHHS OCRas victim2014-02-21
StayWell Health Management, LLC reported to HHS on 2014-02-21 a Unauthorized Access/Disclosure affecting 19,474 individuals. Breached information located on Network Server. Spreadsheets containing PHI (names, emails, program info) were unintentionally available online in a public-facing folder from March 29, 2012, to January 21, 2014. The BA notified HHS, individuals, and media on behalf of multiple Covered Entities.