Back to the register

Spencer’s Gifts LLC Flexible Benefits and Welfare Benefit Plans

ArchivedSubmitted 01/24/2022
State
NJ
Covered entity type
Health Plan
Individuals affected
10,023
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans (the Plan), the employer-sponsored group health plan of Spencer Gifts LLC, a national retail company, over potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules. OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules (HIPAA Rules), which set forth the requirements that covered entities (health plans, health care clearinghouses, and most health care providers), and business associates (collectively, regulated entities) must follow to protect the privacy and security of protected health information (PHI). The risk analysis provision of the HIPAA Security Rule requires regulated entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI (ePHI) held by those organizations. The settlement resolves an investigation that OCR initiated after the Plan filed a breach report on January 24, 2022. The Plan had received employee complaints that employees were unable to connect to the virtual private network. The Plan discovered that in November 2021, an unauthorized actor accessed the company’s network and deployed ransomware, encrypting data on the company’s systems, including servers storing the Plan’s PHI, and demanding a ransom. The PHI of 10,023 individuals was potentially affected by the breach, including health plan members' names, addresses, zip codes, phone numbers, email addresses, and Social Security numbers. OCR found that the Plan had potentially violated provisions of the Privacy and Security Rules, including: Failing to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the Plan prior to the breach incident; and Failing to implement reasonable and appropriate policies and procedures to comply with the HIPAA Privacy, Security, and Breach Notification Rules prior to the breach incident. Under the terms of the resolution, the Plan paid $450,000 and agreed to a two-year corrective action plan monitored by OCR.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.

We use essential cookies to run this site and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.