Terteling Co., Inc., Group Benefit Plan
Disclosed Jul 6, 20188 years ago4,824 affectedConfirmed
The covered entity (CE), a group health plan, reported to OCR that multiple employees responded to a phishing email which compromised the protected health information (PHI) of 4,824 plan members. The types of breached PHI included names, addresses, dates of birth, driver’s license information, social security numbers, claims information, diagnoses, and medications. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE strengthened its administrative and technical safeguards, such as authentication procedures and measures to identify and remove malicious emails. It also increased its security training. As a result of OCR’s investigation the CE enhanced its practices for safeguarding PHI.
What is known
| People affected | 4,824 (as reported to HHS) |
|---|---|
| Disclosed | Jul 6, 2018 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Terteling Co., Inc., Group Benefit Plan (Health Plan, ID)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 6, 2018 | 4,824 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.