Back to the register
Spencer’s Gifts LLC Flexible Benefits and Welfare Benefit Plans
ArchivedSubmitted 01/24/2022
- State
- NJ
- Covered entity type
- Health Plan
- Individuals affected
- 10,023
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans (the Plan), the employer-sponsored group health plan of Spencer Gifts LLC, a national retail company, over potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules.
OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules (HIPAA Rules), which set forth the requirements that covered entities (health plans, health care clearinghouses, and most health care providers), and business associates (collectively, regulated entities) must follow to protect the privacy and security of protected health information (PHI). The risk analysis provision of the HIPAA Security Rule requires regulated entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI (ePHI) held by those organizations.
The settlement resolves an investigation that OCR initiated after the Plan filed a breach report on January 24, 2022. The Plan had received employee complaints that employees were unable to connect to the virtual private network. The Plan discovered that in November 2021, an unauthorized actor accessed the company’s network and deployed ransomware, encrypting data on the company’s systems, including servers storing the Plan’s PHI, and demanding a ransom. The PHI of 10,023 individuals was potentially affected by the breach, including health plan members' names, addresses, zip codes, phone numbers, email addresses, and Social Security numbers. OCR found that the Plan had potentially violated provisions of the Privacy and Security Rules, including:
Failing to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the Plan prior to the breach incident; and
Failing to implement reasonable and appropriate policies and procedures to comply with the HIPAA Privacy, Security, and Breach Notification Rules prior to the breach incident.
Under the terms of the resolution, the Plan paid $450,000 and agreed to a two-year corrective action plan monitored by OCR.
Change history
- 9/23/2026Added to OCR's archive list
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.