On June 27, 2017, Union Labor Life Insurance, the covered entity (CE), discovered that an unauthorized user accessed an employee’s email account. The breach occurred when the employee received an email that purported to be from a trusted user, but contained a virus. The breach affected the protected health information (PHI) of 664 individuals, including social security numbers and clinical information. The CE provided breach notification to HHS, the affected individuals, and the media. Following the breach, the CE retrained staff on phishing and email security, and implemented additional technical safeguards in its email system. OCR obtained assurances that the CE implemented the corrective actions listed, and reviewed the covered entity’s risk analysis to ensure compliance with the Security Rule.
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 664 · backfill source
2026-09-25 · disclosed: 2017-10-27 to 2017-10-19 · backfill source
2026-09-25 · summary: empty to On June 27, 2017, Union Labor Life Insurance, the covered entity (CE), discovered that an unauthorized user accessed an employee’s email account. The breach occurred when the employee received an email that purported to be from a trusted us · backfill source