Back to the register

ConnectiCare

ArchivedSubmitted 02/21/2018
State
CT
Covered entity type
Health Plan
Individuals affected
1,834
Business associate present
Yes
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On January 4, 2018, the covered entity (CE), ConnectiCare, learned that its business associate (BA), RR Donnelly, sent some of their subscribers the wrong identification card. This incident affected 1,834 individuals, exposing demographic and health plan information. OCR reviewed the CE's policies and procedures relevant to this breach and the BA agreement with RR Donnelly. The policies and the BA agreement appear to be in compliance with the Privacy Rule. The CE directed the BA to take actions to address the programming logic error which caused the breach, and the BE implemented additional coding logic on January 24, 2018, to prevent this type of error from occurring again. The CE provided OCR with assurances that individuals affected by this breach and the media were notified in accordance with the Breach Notification Rule.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.