Rocky Mountain Health Maintenance Organization
Disclosed Mar 17, 20179 years ago1,320 affectedConfirmed
On January 23, 2017, the covered entity (CE), Rocky Mountain Health Maintenance Organization, Inc., mailed letters containing protected health information (PHI) to incorrect recipients. The types of PHI involved in the breach included demographic information, and the last four digits of social security numbers or dates of birth for approximately 1,320 individuals. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE investigated the cause of the breach and revised its related HIPAA policies and procedures. OCR obtained assurances that the CE implemented the corrective actions noted above.
What is known
| People affected | 1,320 (as reported to HHS) |
|---|---|
| Disclosed | Mar 17, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Rocky Mountain Health Maintenance Organization (Health Plan, CO)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 17, 2017 | 1,320 |
Other breaches at Rocky Mountain Health Maintenance Organization
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Sep 12, 2019Sep 12, 20197 years agoInsider | Sep 12, 20197 years ago | Insider | Insurance | Confirmed | 1,835 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Rocky Mountain Health Maintenance Organization