- State
- IL
- Covered entity type
- Business Associate
- Individuals affected
- 500
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Prime Therapeutics, a business associate (BA) and pharmacy benefit manager for the covered entity (CE), Ultra Stores, Inc.’s health plan, electronically submitted a file containing the eligibility information for plan members to the Illinois Department of Healthcare and Family Services (IDHFS), as required by law for Medicaid subrogation. Due to a system error during the file generation process, the electronic protected health information (ePHI) of at least 500 plan members who do not reside in Illinois were also included in the file. The ePHI in the mailing included full names, social security numbers, dates of birth, and home addresses. During the investigation, OCR learned that Signet Jewelers had acquired Ultra and, consequently, Ultra’s health plan no longer exists. Additionally, Sterling Jewelers (Sterling), a business unit of Signet, informed OCR that it believes that Ultra had erroneously reported the September 13, 2012 incident to OCR, as Prime had conducted a risk assessment and had determined that the incident was not a breach, as the file in issue was not accessed or viewed by anyone at IDHFS. OCR obtained and reviewed documentation indicating that, in response to the incident, the BA obtained confirmation from IDHFS that it destroyed the file and that it did not further disclose the file. The BA also corrected the system error and implemented changes to the file generation process to prevent the same error from recurring
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.