DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Brand New Day notifies 14,005 members after breach at vendor

Posted on March 10, 2017 by Dissent

From their press release of March 10:

Universal Care, Inc. dba Brand New Day (BND) announced today that it has notified individuals related to a privacy incident involving information stored by a third-party vendor. The incident did not involve information that was stored or maintained on BND’s own systems.

On December 28, 2016, BND learned that an unauthorized individual gained access to electronic files stored on computer systems maintained by a third-party vendor that provides patient management software applications to BND and its providers. This incident was reported by BND to law enforcement. Thereafter, law enforcement investigators required that any notification to potentially affected individuals and any public announcement of the incident should be withheld while they were conducting their investigation. Following law enforcement’s permission to notify, BND began this notification as quickly as possible once BND had completed its investigation.

Based on BND’s investigation, it was determined that the files stored by the third-party vendor contained personal information on BND members, including patient names, addresses, phone numbers, dates of birth and Medicare ID numbers. It does not appear that driver’s license numbers or California identification card numbers were involved in the information that was accessed.

BND is committed to the security of all sensitive information maintained by its third-party vendors and is taking this matter very seriously. To help prevent this type of incident from happening again, BND contacted the third party vendor the same day we became aware of the breach to advise them of the breach.  The vendor eliminated the error in their system within hours. BND will also request its third-party vendor to take steps to enhance the security of its systems that maintain BND patient data. As an added precaution, BND is offering 12 free months of identity theft and mitigation services to affected individuals to help prevent and detect misuse of their personal information. To obtain information on how to access these services, please contact the any of the individuals named below.

We regret any inconvenience caused by this incident. We began mailing notification letters to affected individuals on March 9, 2017. If you believe you may be affected and have not received a letter by March 31, 2017, or to obtain information regarding the offer for identity theft and mitigation services or if you need any other information or wish to contact us with concerns, please call us at any of the following numbers, Monday through Friday, 9 a.m. to 7 p.m. PST (closed on U.S. observed holidays):

Jonathan Devin Wheeler, J.D.

Compliance Analyst

P.O. Box 93122

Long Beach, CA 90809-9871

866-255-4795, ext. 4078

Connie Snyder

Compliance Officer

P.O. Box 93122

Long Beach, CA 90809-9871

866-255-4795, ext. 5054

Source: Universal Care, Inc. dba Brand New Day

The incident was reported to HHS on February 10 as affecting 14,005 patients. Because the vendor is not named, it is not known whether any other healthcare entities have also been affected, but in its notification to the California Attorney General’s Office, they offer the following additional details:

A contracting provider was able to access (via a third party vendor system) data containing your name, date of birth, Medicare ID number, address, and phone number. This information should have been available only to your provider.

BND also disclosed in the notification to the AG’s Office that the incident occurred on December 22, 2016.


Related:

  • Snowflake Loses Two More Bids to Dismiss Data Breach Plaintiffs
  • US company with access to biggest telecom firms uncovers breach by nation-state hackers
  • Safaricom-Backed M-TIBA Victim of a Possible Data Breach Affecting Millions of Kenyans
  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
  • NY: Gloversville hit by ransomware attack, paid ransom
  • Two U.K. teenagers appear in court over Transport of London cyber attack
Category: Health DataSubcontractorU.S.

Post navigation

← Denton Heart Group notifies patients stolen hard drive held 7 years’ worth of PII/PHI
VCU Health System notifies 2,700 of inappropriate access to their medical records →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.