Capitol Administrators, Inc
ent_d97aff0e720b12b423d4c7b7
Disclosures
2
HHS OCR · State AG · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,733
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Capitol Administrators, Inc
- Normalized
- capitol administrators— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- CALIFORNIAHHS OCRas victim2018-05-11
Capitol Administrators, Inc. (a Business Associate in CA) reported to HHS on 2018-05-11 a Hacking/IT Incident affecting 1,733 individuals. An external third party accessed employees' email accounts via a suspected phishing incident, compromising demographic and clinical PHI. The BA notified client health plans, HHS, affected individuals, and media, and offered free credit monitoring. Remediation included password changes, MFA implementation, blocking foreign IP addresses, and enhanced phishing training. Breached information located on Email.
- California State AGas victim2018-05-11
Capitol Administrators, Inc. reported a data breach resulting from a phishing email incident. On March 30, 2018, the company discovered that an unauthorized individual had accessed emails and attachments in a small number of employee accounts. The breach window was identified as January 7–24, 2018. Affected data included names and personal/medical information of plan participants. Capitol engaged a cybersecurity firm, secured accounts, implemented MFA, and offered one year of identity monitoring via Kroll.