Skip to content

Healthfirst Affiliates that include Healthfirst PHSP, Inc., Managed Health, Inc., HF Management Services, LLC, and Senior Health Partners

Disclosed Jul 24, 201511 years ago5,338 affectedConfirmed

Official notice

On May 27, 2015, the U.S. Department of Justice (DOJ) informed the covered entity (CE), Healthfirst, that an individual who perpetrated a fraud against the CE in 2013 may have stolen 5,338 patients’ electronic protected health information (ePHI) from the CE’s online portal. The types of stolen ePHI included demographic, clinical, and claims information, including Medicare and Medicaid identification numbers. The CE provided breach notification to HHS, the affected individuals and the media. Following the breach, the CE strengthened security controls on its online portal and implemented multifactor validation for provider access to the portal. OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, the CE is expected to conduct a risk analysis, implement a corresponding remediation plan, and ensure the implementation of policies and procedures relating to information system activity review, security incident response and reporting, access and audit controls, and creating/maintaining retrievable exact copies of ePHI.

What is known

People affected5,338 (as reported to HHS)
DisclosedJul 24, 2015
AttackHacking
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJul 24, 20155,338
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Healthfirst Affiliates that include Healthfirst PHSP, Inc., Managed Health, Inc., HF Management Services, LLC, and Senior Health Partners

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.