In March 2017, an employee of National DCP Health Plan (GA, Health Plan) followed a link in a phishing email, resulting in an unauthorized external actor accessing her email account. PHI exposed for 1,190 individuals included health plan enrollment data: names, addresses, SSNs, and dates of birth. The CE notified HHS, affected individuals, and posted notice on its website; it also reported to the FBI and Secret Service. OCR investigated and obtained assurances that the CE implemented MFA for email, improved inbound email safeguards, and conducted phishing awareness training for its workforce. Breached information located on Email.
Affected (this filing): 1,190