Triple-S Salud, Inc.
ent_b35f0edf166ebe996c820ace
Disclosures
8
HHS OCR · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
398,000
nationwide · HHS OCR PR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Triple-S Salud, Inc.
- Normalized
- triple s salud— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- salud.grupotriples.com
Disclosure history (8)newest first
- FEDERALHHS OCRas victim2014-07-18
Administracion de Seguros de Salud - Triple S Salud Inc (BA) reported to HHS on 2014-07-18 a breach involving unauthorized access/disclosure affecting 7,911 individuals. The incident occurred when a former employee of a business associate copied patient enrollment information onto a portable disk and downloaded it to a personal computer. The breached data included names, dates of birth, addresses, Social Security numbers, and health insurance claim numbers.
- PRHHS OCRas victim2014-05-29
Triple-S Salud (a subsidiary of Triple-S Management Corporation, a Puerto Rico-based health insurer) reported to HHS OCR on 2014-05-29 an Unauthorized Access/Disclosure breach affecting 56,853 individuals, with breached information located on Paper/Films. OCR investigations revealed widespread HIPAA non-compliance: impermissible PHI disclosures to a vendor lacking a business associate agreement, disclosure of more PHI than necessary for mailings, and inadequate safeguards. Triple-S settled for $3.5 million and adopted a Corrective Action Plan.
- PRHHS OCRas victim2014-04-15
On March 27, 2014, Puerto Rico Health Insurance Administration reported to HHS a Theft affecting 46,473 individuals. A former employee of Triple-S Advantage Solutions (BA of Triple-S Salud) copied beneficiaries' ePHI—names, DOBs, contract numbers, HICN, home addresses, and SSNs—onto a CD before October 9, 2013, later downloading it at a new employer. Discovery occurred January 14, 2014. Breached info was on an Other Portable Electronic Device. OCR investigation led to risk analysis, policy revisions, and staff retraining commitments.
- PRHHS OCRas victim2014-04-15
Triple S Salud Inc. reported to HHS on 2014-04-15 a Theft affecting 7911 individuals. Breached information located on Other Portable Electronic Device.
- FEDERALHHS OCRas victim2014-04-02
Triple-S Salud (a subsidiary of Triple-S Management Corporation, a Puerto Rico health insurer) reported to HHS OCR on 2014-04-02 a Theft breach affecting 5,795 individuals. Breached PHI was located on 'Other' media. OCR investigations found widespread HIPAA non-compliance including failure to safeguard PHI, impermissible disclosures to a vendor lacking a BAA, and excess PHI use in mailings. Triple-S settled for $3.5 million and adopted a corrective action plan.
- PRHHS OCRas victim2014-01-24
Triple-S Salud, Inc. reported to HHS on 2014-01-24 a Theft affecting 398000 individuals. Breached information located on Network Server. The incident involved impermissible disclosure of PHI to an outside vendor without a business associate agreement. Triple-S paid a $3.5 million settlement and implemented a comprehensive HIPAA compliance program including risk analysis, training, and policy updates.
- FEDERALHHS OCRas victim2013-11-08
Triple-S Salud, Inc. (business associate of Puerto Rico Health Insurance Administration / Administración de Seguros Salud de Puerto Rico) was reported to HHS on 2013-11-08 for an Unauthorized Access/Disclosure affecting 13,336 individuals. On September 20, 2013, a vendor of Triple-S Salud mailed pamphlets that displayed PHI (names, mailing addresses, health insurance claim numbers) on the outside. Discovery occurred September 23, 2013. Breached information located on Paper/Films. OCR investigation resulted in CE commitments to risk analysis, risk management planning, policy revision, and staff retraining.
- FEDERALHHS OCRas victim2010-11-18
Triple-S Management Corporation, on behalf of its subsidiaries including Triple-S Salud Inc., agreed to a $3.5 million settlement with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) for potential HIPAA violations. Following multiple breach notifications, OCR investigations found widespread non-compliance, including failure to implement proper safeguards, impermissible disclosure of PHI to a vendor without a business associate agreement, disclosing more PHI than necessary, and failure to conduct a thorough risk analysis. The settlement requires a comprehensive corrective action plan to address these deficiencies.