- State
- MA
- Covered entity type
- Health Plan
- Individuals affected
- 1,715
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An unknown third party used social engineering to obtain the identifying information of eleven employees from sources outside their employment and used that information to impersonate the employees online and over the phone to gain access to a database of the covered entity (CE). The database contained the protected health information (PHI) of 1,715 long-term care insurance policy holders and applicants. including names, dates of birth, Social Security numbers, telephone numbers, email addresses and certain long-term care insurance policy information. Following the breach, the CE took the database offline, created new identity verification policies and procedures, and retrained staff. The CE provided breach notification to HHS and affected individuals in accordance with the Breach Notification Rule. OCR provided the CE with technical assistance regarding its privacy and security program.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.