Back to the register

Healthfirst Affiliates that include Healthfirst PHSP, Inc., Managed Health, Inc., HF Management Services, LLC, and Senior Health Partners

ArchivedSubmitted 07/24/2015
State
NY
Covered entity type
Health Plan
Individuals affected
5,338
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Electronic Medical Record
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On May 27, 2015, the U.S. Department of Justice (DOJ) informed the covered entity (CE), Healthfirst, that an individual who perpetrated a fraud against the CE in 2013 may have stolen 5,338 patients’ electronic protected health information (ePHI) from the CE’s online portal. The types of stolen ePHI included demographic, clinical, and claims information, including Medicare and Medicaid identification numbers. The CE provided breach notification to HHS, the affected individuals and the media. Following the breach, the CE strengthened security controls on its online portal and implemented multifactor validation for provider access to the portal. OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, the CE is expected to conduct a risk analysis, implement a corresponding remediation plan, and ensure the implementation of policies and procedures relating to information system activity review, security incident response and reporting, access and audit controls, and creating/maintaining retrievable exact copies of ePHI.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.