- State
- CT
- Covered entity type
- Health Plan
- Individuals affected
- 1,834
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On January 4, 2018, the covered entity (CE), ConnectiCare, learned that its business associate (BA), RR Donnelly, sent some of their subscribers the wrong identification card. This incident affected 1,834 individuals, exposing demographic and health plan information. OCR reviewed the CE's policies and procedures relevant to this breach and the BA agreement with RR Donnelly. The policies and the BA agreement appear to be in compliance with the Privacy Rule. The CE directed the BA to take actions to address the programming logic error which caused the breach, and the BE implemented additional coding logic on January 24, 2018, to prevent this type of error from occurring again. The CE provided OCR with assurances that individuals affected by this breach and the media were notified in accordance with the Breach Notification Rule.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.