Back to the register
Puerto Rico Department of Health - Triple S Management Corp.
ArchivedSubmitted 11/04/2010
- State
- PR
- Covered entity type
- Health Plan
- Individuals affected
- 475,000
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On November 5, 2010, the Puerto Rico Department of Health (DOH), a hybrid entity, reported on behalf of the covered entity (CE), Puerto Rico Health Insurance Administration, also known as the Administracion de Seguros Salud de Puerto Rico, that it discovered that two former staff members of the business associates (BAs) Triple-S Salud (TSS) and Triple-C, improperly accessed restricted areas of TSS’ proprietary internet IPA database managed by Triple-C, Inc. The staff members, who were employed by a competitor, were able to gain access to the database because their access rights were not terminated upon leaving the employment of TSS. As a result, the electronic protected health information in the database, including 400,000 of the CE’s members’ names, contract numbers, home addresses, diagnostic codes, and treatment codes, was accessed. DOH provided breach notification to HHS, and TSS provided breach notification to affected individuals, and the media. Due to OCR’s investigation, the CE committed to conduct a risk analysis, implement a risk management plan, revise its policies and procedures, and retrain its staff within a specified period.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.