An employee of business associate Centene Management Company downloaded data files containing PHI of 8,208 individuals to an unauthorized removable storage device before resigning. The employee returned a company-issued laptop on 2015-03-23, but it was not connected to the network for processing per standard procedure, delaying detection. On 2015-10-08, a data loss prevention tool discovered the impermissible downloads when the laptop was finally connected. PHI included names, addresses, dates of birth, medical ID numbers, and in some cases SSNs. Affected members were enrollees of covered entities Bridgeway Health Solutions and Superior Health Plan. The BA notified HHS, affected individuals, and media, and provided substitute notice. Remediation included new IT-equipment processing policy and DLP controls preventing downloads to unauthorized external storage. OCR provided technical assistance on Security Rule risk analysis/management.
Affected (this filing): 8,208