Managed Health Services
ent_da2a56e8ad65267a1fefff74
Disclosures
4
HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
31,300
nationwide · HHS OCR IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Managed Health Services
- Normalized
- managed health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- INDIANAHHS OCRas victim2019-01-03
Managed Health Services (IN), a Health Plan, reported to HHS on 2019-01-03 an Unauthorized Access/Disclosure affecting 576 individuals. An employee mailed PHI — including names, medications, and health insurance information — to the wrong recipient. Breached information was on Paper/Films. The CE notified HHS, affected individuals, and the media, offered credit monitoring, and retrained all staff while implementing additional safeguards.
- INDIANAHHS OCRas victim2019-01-03
Managed Health Services reported to HHS on 2019-01-03 a Hacking/IT Incident affecting 31,300 individuals. Breached information located on Email. Employees of a business associate were victims of an email phishing attack exposing PHI (names, DOB, addresses, diagnoses). The CE provided credit monitoring and the BA implemented security safeguards.
- INDIANAHHS OCRas victim2016-11-29
Managed Health Services (IN, Health Plan) reported to HHS OCR on 2016-11-29 an Unauthorized Access/Disclosure affecting 5,500 individuals. A contract employee improperly emailed Excel files containing PHI — including names, addresses, dates of birth, diagnoses/conditions, clinical information, and medications — to his personal email account. Breached info was located on Email and Laptop. The CE sanctioned the employee, implemented technical safeguards, and completed OCR-required focused HIPAA Privacy Rule training. OCR obtained assurances of corrective action.
- FEDERALHHS OCRas victim2016-05-01
On March 13, 2016, Managed Health Services (IN, Health Plan) discovered that a CRM export file dated February 24, 2016 mismatched member addresses, causing New Member Packets and ID cards — containing names, Medicaid ID numbers, and PHI — to be mailed to incorrect recipients, including members of its Ohio sister plan. Approximately 610 individuals were affected. The CE corrected the export error, improved QA procedures, implemented new technical safeguards, notified HHS/media/affected individuals, and provided workforce training. OCR obtained documented assurances of corrective action. Breached information located on Paper/Films.