Back to the register
Healthfirst Affiliates that include Healthfirst PHSP, Inc., Managed Health, Inc., HF Management Services, LLC, and Senior Health Partners
ArchivedSubmitted 07/24/2015
- State
- NY
- Covered entity type
- Health Plan
- Individuals affected
- 5,338
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On May 27, 2015, the U.S. Department of Justice (DOJ) informed the covered entity (CE), Healthfirst, that an individual who perpetrated a fraud against the CE in 2013 may have stolen 5,338 patients’ electronic protected health information (ePHI) from the CE’s online portal. The types of stolen ePHI included demographic, clinical, and claims information, including Medicare and Medicaid identification numbers. The CE provided breach notification to HHS, the affected individuals and the media. Following the breach, the CE strengthened security controls on its online portal and implemented multifactor validation for provider access to the portal. OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, the CE is expected to conduct a risk analysis, implement a corresponding remediation plan, and ensure the implementation of policies and procedures relating to information system activity review, security incident response and reporting, access and audit controls, and creating/maintaining retrievable exact copies of ePHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.