Cno Ace
ent_5658b574861041ad7cf249c7
Disclosures
4
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
566,217
nationwide · HHS OCR IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cno Ace
- Normalized
- cno ace— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- INDIANAHHS OCRas victim2024-01-26
CNO ACE reported to HHS on 2024-01-26 a Hacking/IT Incident affecting 65,295 individuals. Breached information located on Network Server. The PHI involved included names, dates of birth, Social Security numbers, and policy numbers. The CE provided complimentary identity protection services and implemented additional administrative and technical safeguards.
- Illinois State AGas victim2021-01-01
CNO ACE filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-109). The register records the breach as discovered on February 26, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
CNO ACE filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-318). The register records the breach as discovered on June 16, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- INDIANAHHS OCRas victim2018-10-25
CNO ACE (Health Plan, IN) reported to HHS on 2018-10-25 a Hacking/IT Incident affecting 566,217 individuals. Breached information was located on a Network Server. The cyber-attack exposed ePHI including names, addresses, dates of birth, health insurance information, and Social Security numbers. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website, and implemented additional administrative, technical, and security safeguards.