Business Associate Notifies Individuals of HIPAA Breach

Posted by BAS - 10 October, 2013

header-picture

A third-party debt collection agency, which acted as a business associate to a University of Chicago Physicians Group, encountered a breach under HIPAA and had to notify 1,400 individuals that their information was compromised.

The debt collection agency received a notice from an individual that a user on its website could view sensitive information relating to other debtors. This information included patient name, address, Social Security Number, date of birth, insurance policy information, diagnosis, among others. The agency conducted an internal investigation and confirmed the breach.

The agency made the required notifications to impacted individuals and the Department of Health and Human Services.

Topics: MyEnroll360 Security


Recent Posts

“Wait—Can Ally Really Answer That?” Surprising (But True) Questions Our AI Can Handle

read more

Question of the Week - Missed COBRA Notice

read more

Fraud Prevention in Benefits Administration: Protecting Plans and Participants

read more