SCAN Health Plan reported a data breach to the Montana Attorney General. The breach was reported on 2016-08-22. The breach occurred from 3/4/2016 to 6/24/2016. 6 Montana residents were affected.
Affected (this filing): 6
Clustered 3 filings across 2 jurisdictions · filed Aug 22, 2016. View entity profile → Other incidents for this victim →
incident inc_ef4e7a8022194c18 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
CA MT
HHS OCR · State AG
Earliest sighting first · deep chronology in Litigation Timeline
Mar 4, 2016
When the intrusion reportedly occurred, per the linked filings
Jun 27, 2016
Reported by CALIFORNIA AG filing
SCAN Health Plan reported a data breach to the Montana Attorney General. The breach was reported on 2016-08-22. The breach occurred from 3/4/2016 to 6/24/2016. 6 Montana residents were affected.
Affected (this filing): 6
SCAN Health Plan notified California regulators of unauthorized access to a sales system between March and June 2016. Affected individuals had their name, address, phone, SSN, DOB, and limited health info exposed. SCAN engaged outside experts and provided one year of free identity protection services via AllClear ID.
SCAN Health Plan reported to HHS on 2016-08-22 a Unauthorized Access/Disclosure affecting 87,069 individuals. Breached information located on Other. Internal personnel impermissibly accessed a sales database containing PHI, including names, addresses, DOBs, SSNs, and clinical notes. Remediation included enhanced database monitoring and authentication procedures.
Affected (this filing): 87,069
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.