Puerto Rico Health Insurer Reports Record Fine Following PHI Breach Incident
Time 2 Minute Read

Triple-S Management Corporation reported in the 8-K it recently filed with the U.S. Securities and Exchange Commission that its health insurance subsidiary, Triple-S Salud, Inc. (“Triple S”), which is Puerto Rico’s largest health insurer, will be fined $6.8 million for a data breach that occurred in September 2013. The civil monetary penalty, which is being levied by the Puerto Rico Health Insurance Administration, will be the largest fine ever imposed following a breach of protected health information.

According to the filing, in September 2013, Triple S mailed pamphlets to its Medicare Advantage beneficiaries that inadvertently displayed the beneficiaries’ Medicare Health Insurance Claim Numbers. Following the breach, which affected more than 13,000 individuals, Triple S conducted an investigation, notified affected individuals and reported the incident to Puerto Rican authorities as well as the Department of Health and Human Services’ Office for Civil Rights. Triple S also offered one year of credit monitoring at no charge to the affected individuals.

According to the 8-K, Triple S was notified of the pending sanctions on February 11, 2014. In addition to the proposed monetary penalty, Triple S will be required to suspend new enrollments of Dual Eligible Medicare beneficiaries and notify existing beneficiaries of their right to disenroll from the Triple S Medicare Advantage plan. In the 8-K, Triple S noted that it is responding to the allegations that it “failed to take all required steps in response to the breach” and has the right to request an administrative hearing on the issue. The 8-K concluded by noting that Triple S is “working to prevent this type of incident from happening again.”

View the 8-K.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page