Healthfirst Affiliates that include Healthfirst PHSP, Inc., Managed Health, Inc., HF Management Services, LLC, and Senior Health Partners
Disclosed Jul 24, 201511 years ago5,338 affectedConfirmed
On May 27, 2015, the U.S. Department of Justice (DOJ) informed the covered entity (CE), Healthfirst, that an individual who perpetrated a fraud against the CE in 2013 may have stolen 5,338 patients’ electronic protected health information (ePHI) from the CE’s online portal. The types of stolen ePHI included demographic, clinical, and claims information, including Medicare and Medicaid identification numbers. The CE provided breach notification to HHS, the affected individuals and the media. Following the breach, the CE strengthened security controls on its online portal and implemented multifactor validation for provider access to the portal. OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, the CE is expected to conduct a risk analysis, implement a corresponding remediation plan, and ensure the implementation of policies and procedures relating to information system activity review, security incident response and reporting, access and audit controls, and creating/maintaining retrievable exact copies of ePHI.
What is known
| People affected | 5,338 (as reported to HHS) |
|---|---|
| Disclosed | Jul 24, 2015 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Healthfirst Affiliates that include Healthfirst PHSP, Inc., Managed Health, Inc., HF Management Services, LLC, and Senior Health Partners (Health Plan, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 24, 2015 | 5,338 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.