Back to the register

Newkirk Products, Inc.

ArchivedSubmitted 08/09/2016
State
NY
Covered entity type
Business Associate
Individuals affected
3,466,120
Business associate present
Yes
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Soon after its acquisition by a new parent company, the business associate (BA), Newkirk Products, Inc., learned that, prior to the acquisition, unauthorized individuals had accessed a computer server containing the electronic protected health information (ePHI) of 3,992,270 members of health plans and claims administrators on whose behalf the BA issues member healthcare identification (ID) cards. The ePHI consisted of some combination of the member’s name, mailing address, type of plan, member and group ID number, names of dependents enrolled in the plan, primary care provider, and in some cases, Medicaid ID number, dates of birth and premium invoice information. The BA provided breach notification to HHS, the media, its health plan clients, and the affected individuals (including the offer of two years of identity protection restoration services at no cost to the affected individuals), and posted notice to its website. Following the breach, the BA contacted law enforcement and conducted a forensic investigation, and the former parent company decommissioned the affected server. The BA also set up a new information technology environment, including newly built computer servers and storage, protected by the new parent company’s existing information security controls. The BA also ensured that only authorized client internet protocol (IP) addresses are permitted entry to the new server and trained its workforce members on HIPAA. OCR obtained assurances that the BA implemented the corrective actions listed. Additionally, the BA is expected to conduct a risk analysis, implement a corresponding remediation plan, and ensure the implementation of policies and procedures relating to information system activity review, security incident response and reporting, access and audit controls, and creating/maintaining retrievable exact copies of ePHI.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.