- State
- FL
- Covered entity type
- Business Associate
- Individuals affected
- 40,621
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 20, 2017, an information technology subcontractor for MedWatch, a business associate (BA), applied a misconfigured security patch to an online portal during a routine update causing some protected health information (PHI) to be viewable by the public. The breach affected 40,621 individuals who are members of the BA’s client health plans and third party administrators. The exposed PHI included various combinations of members’ demographic and health insurance information. Upon discovery of the breach on December 15, 2017, the BA immediately restricted access to the portal and requested that internet search engines remove all cached data. The BA notified its client covered entities and provided breach notification to HHS, affected individuals, and the media and posted substitute notice on its website. The BA improved technical safeguards, updated its policies, and retrained all staff and contractors on HIPAA Privacy and Security. OCR obtained assurances that the BA implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.