- State
- MO
- Covered entity type
- Health Plan
- Individuals affected
- 8,208
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An employee of a business associate (BA), Centene Management Company, impermissibly downloaded several data files containing the protected health information (PHI) of 8,208 individuals to an unauthorized removable storage device and then resigned from the organization. The former employee returned his company issued laptop on March 23, 2015. However, in violation of standard procedures, the laptop was not connected to the network for processing/reimagining at the time it was returned which allowed the impermissible downloads to go undetected. On October 8, 2015, a data loss prevention tool discovered the impermissible downloads when the former employee’s laptop was connected to the network for processing. The PHI involved in the breach included names, addresses, dates of birth, medical identification numbers, and in some cases social security numbers. The PHI downloaded belonged to members of the covered entities, Bridgeway Health Solutions and Superior Health Plan. The BA provided breach notification to HHS, affected individuals, and the media and also provided substitute notice. In response to the breach, the BA implemented and communicated a policy to help ensure the timely processing of returned information technology equipment. It also implemented a policy and software solution prohibiting the downloading of data to unauthorized, external storage. OCR provided technical assistance regarding the risk analysis and risk management provisions of the Security Rule.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.