- State
- MN
- Covered entity type
- Business Associate
- Individuals affected
- 10,024
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On February 21, 2014, StayWell Health Management, LLC, a business associate (BA) of the covered entity (CE), Missouri Consolidated Health Care Plan, erroneously made a spreadsheet accessible via an electronic link on the internet. The spreadsheet included participants’ complete names, email addresses, unique internal identification numbers, current status in the wellness program, information regarding email notifications, and whether a participant had completed two program surveys. Approximately 10,024 individuals were affected by the breach. The BA provided breach notification to affected individuals and the media. The CE provided breach notification to HHS. Following the breach, the CE ensured that the BA removed the spreadsheet from public accessibility via the internet and implemented the use of a legacy system in order to safeguard electronic protected health information (ePHI) in transit. The CE also updated its Privacy and Security Policy, to include encryption standards for safeguarding data in process, in transit, and at rest. OCR obtained documented assurances that the CE and BA implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.