DMBA (Health Plan, UT) reported to HHS on 2020-12-02 an Unauthorized Access/Disclosure affecting 774 individuals. An employee was the victim of an email phishing scheme that compromised ePHI stored on a Desktop Computer. Exposed data included names, Social Security numbers, dates of birth, and financial and claims information. The CE notified HHS, affected individuals, and the media, implemented enhanced safeguards, and retrained staff on identifying fraudulent emails. OCR provided technical assistance and obtained assurances of corrective action.
Affected (this filing): 774