Jacobsen Construction Co., Inc. Health Plan Data Breach
Jacobsen Construction Health Plan Network Server Breach
What happened in the Jacobsen Construction Co., Inc. Health Plan data breach?
The Jacobsen Construction Co., Inc. Health Plan data breach was reported on September 20, 2024 and affected 2,127 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Utah. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Jacobsen Construction Co., Inc. Health Plan Breach Details
Jacobsen Construction Co., Inc. Health Plan Data Breach Report
Breach Overview
On September 20, 2024, Jacobsen Construction Co., Inc. Health Plan reported a significant data breach affecting 2,127 individuals in Utah. The breach resulted from unauthorized access to the organization's network server infrastructure, compromising protected health information (PHI) and personal data maintained by the health plan. This incident represents a hacking or IT-related security compromise rather than physical theft or loss, indicating that attackers gained unauthorized electronic access to systems containing sensitive employee and dependent health information.
Company Response and Investigation
Upon discovery of the unauthorized access to their network server, Jacobsen Construction Co., Inc. Health Plan initiated a comprehensive investigation to determine the scope and nature of the breach. The organization worked to identify which systems were compromised, what data was accessed, and the timeline of the unauthorized activity. As required under the Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule, the health plan notified affected individuals of the breach. The submission date of September 20, 2024, indicates when the breach was formally reported to regulatory authorities, though the actual discovery and investigation period may have occurred in the preceding weeks or months. The organization implemented remediation measures to secure their network infrastructure and prevent similar incidents from occurring in the future.
Technical Details of the Breach
Network server breaches typically occur through various attack vectors including exploitation of unpatched software vulnerabilities, weak authentication credentials, phishing attacks targeting employee credentials, or misconfigured security settings. When a network server is compromised, attackers gain access to centralized data repositories where health plan information is stored and processed. This location type suggests the breach affected backend systems rather than isolated endpoints, potentially exposing larger volumes of data simultaneously. The fact that no business associate was involved indicates that Jacobsen Construction Co., Inc. Health Plan directly managed the compromised systems, making them solely responsible for the security controls that failed. Network server compromises are particularly concerning because they can provide attackers with broad access to multiple data types and systems simultaneously, depending on the attacker's level of privilege escalation and the duration of their unauthorized access.
Organizational Context
Jacobsen Construction Co., Inc. Health Plan operates as an employer-sponsored health benefit plan serving employees and dependents of Jacobsen Construction Co., Inc., a construction industry company based in Utah. As a health plan administrator, the organization maintains comprehensive health records, claims information, and personal identifiers for plan members. The health plan is responsible for managing enrollment, processing claims, coordinating benefits, and maintaining the confidentiality and security of all PHI in accordance with HIPAA regulations. The breach affected individuals within Utah, indicating the organization's primary service area, though the actual membership may extend beyond state lines. The construction industry context is relevant because construction companies typically employ a diverse workforce with varying levels of technical sophistication, and health plan administration may not be the organization's primary focus, potentially affecting the resources dedicated to cybersecurity infrastructure.
Impact on Affected Individuals
The breach impacted 2,127 individuals who were enrolled in or covered by the Jacobsen Construction Co., Inc. Health Plan at the time of the unauthorized access. These individuals likely include active employees, retirees, and their dependents who rely on the health plan for coverage. Each affected person received notification of the breach as required by HIPAA regulations, informing them of the unauthorized access, the types of information compromised, and recommended protective measures. The notification process, which must occur without unreasonable delay and no later than 60 calendar days after discovery of the breach, ensures that individuals have timely information to monitor their accounts and take preventive action. Affected individuals should assume that their personal health information may have been accessed by unauthorized parties and should remain vigilant for potential misuse.
Data Exposure and Risk Assessment
While the specific data elements accessed during this network server breach have not been detailed in the public submission, health plan breaches typically expose multiple categories of protected health information. Likely exposed data may include names, Social Security numbers, dates of birth, health insurance policy numbers, medical record numbers, healthcare provider information, diagnoses and treatment history, prescription information, and claims data. Some individuals may have had financial information exposed, including bank account details or payment card information if such data was stored on the compromised network server. The exposure of this combination of data creates significant identity theft and fraud risks, as attackers possess sufficient information to impersonate individuals, open fraudulent accounts, or commit medical identity theft. The health plan context means that exposed information is particularly valuable to criminals, as it combines personal identifiers with health information that can be used for targeted fraud schemes.
HIPAA Compliance and Industry Context
Under the HIPAA Security Rule, covered entities like health plans must implement administrative, physical, and technical safeguards to protect electronic PHI (ePHI). Network server breaches indicate a failure in one or more of these safeguard categories—whether through inadequate access controls, insufficient encryption, poor patch management, or weak authentication mechanisms. The Breach Notification Rule requires covered entities to notify affected individuals, the media (if more than 500 residents are affected in a jurisdiction), and the U.S. Department of Health and Human Services (HHS) of breaches of unsecured PHI. Network server compromises represent a significant portion of healthcare data breaches, with hacking and IT incidents consistently ranking among the top breach causes in healthcare. The 2,127 individuals affected in this incident places it in the medium-severity range for healthcare breaches, though the sensitivity of health plan data elevates the actual risk to individuals. Similar breaches affecting health plans and health insurers have exposed millions of individuals in recent years, highlighting the ongoing vulnerability of centralized health information repositories to cyber attacks.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Jacobsen Construction Co., Inc. Health Plan Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with each bureau to prevent unauthorized credit applications.
Review explanation of benefits (EOB) statements and health plan claims carefully for any services or treatments you did not receive. Contact your health plan immediately if you identify fraudulent claims or unauthorized healthcare services.
Change passwords for your health plan account and any associated online portals. Use strong, unique passwords and enable multi-factor authentication if available. Do not reuse passwords across different accounts.
Monitor financial accounts, including bank accounts and credit cards, for unauthorized transactions. Set up account alerts with your financial institutions and consider placing a temporary freeze on accounts if suspicious activity is detected.
Be cautious of unsolicited communications claiming to be from your health plan, healthcare providers, or financial institutions. Do not click links or provide information in response to suspicious emails, texts, or phone calls. Verify communications by contacting organizations directly using known phone numbers or websites.
Consider enrolling in credit monitoring or identity theft protection services, which may be offered free by the health plan as part of breach remediation. These services can provide early warning of fraudulent activity.
Retain copies of all breach notification letters and documentation for your records. Document any fraudulent activity you discover and report it to the Federal Trade Commission (FTC) at IdentityTheft.gov.
Review your health insurance coverage and consider whether additional coverage or riders are needed. Ensure your health plan information is accurate and up-to-date to prevent claim denials or coverage issues.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Utah Breaches
Search all breaches reported in Utah