Affinity Health Plan, Inc.
ent_3487388e2211fc43d66e6eb9
Disclosures
2
HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
344,579
as filed · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Affinity Health Plan, Inc.
- Normalized
- affinity health plan— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- FEDERALHHS OCRas victim2015-09-14
Affinity Health Plan, Inc. mistakenly sent renewal letters to 497 heads of household and 224 children that contained other members’ names, addresses, identification numbers, and coverage information. In response, the company placed a hold on outgoing bulk mailings, revised its mailing procedures to comply with minimum necessary and quality standards, and retrained all staff on the updated policies. OCR investigated and obtained assurances that the corrective actions were implemented.
- NEW YORKHHS OCRas victim2010-04-14
Affinity Health Plan, Inc. (NY) reported to HHS OCR on 2010-04-14 a Theft/improper disposal breach affecting 344,579 individuals. Breached information was stored on photocopier hard drives that were returned to leasing agents without data erasure; CBS Evening News discovered the data on a purchased copier and alerted Affinity. OCR found Affinity failed to include photocopier ePHI in its risk analysis. A $1,215,780 settlement and corrective action plan were reached with HHS.