Skip to content

ConnectiCare

Disclosed Feb 21, 20188 years ago1,834 affectedConfirmed

Official notice

On January 4, 2018, the covered entity (CE), ConnectiCare, learned that its business associate (BA), RR Donnelly, sent some of their subscribers the wrong identification card. This incident affected 1,834 individuals, exposing demographic and health plan information. OCR reviewed the CE's policies and procedures relevant to this breach and the BA agreement with RR Donnelly. The policies and the BA agreement appear to be in compliance with the Privacy Rule. The CE directed the BA to take actions to address the programming logic error which caused the breach, and the BE implemented additional coding logic on January 24, 2018, to prevent this type of error from occurring again. The CE provided OCR with assurances that individuals affected by this breach and the media were notified in accordance with the Breach Notification Rule.

What is known

People affected1,834 (as reported to HHS)
DisclosedFeb 21, 2018
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): ConnectiCare (Health Plan, CT)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalFeb 21, 20181,834

Other breaches at ConnectiCare

BreachAffected
Disclosed May 16, 2022May 16, 20224 years agoInsider1,196
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about ConnectiCare

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.