P2018-ND-086

Sun Life Financial

On November 15, 2016, an employee of the Organization inadvertently sent a client a pdf file containing his own coverage summary along with those for 28 other clients. A second client was inadvertently emailed a pdf file containing his own coverage summary along with those for 56 other clients. The first recipient reported the error to his Plan Sponsor on January 11, 2017. The Plan Sponsor informed the Organization on the same date. The second recipient terminated employment with the Plan Sponsor on November 30, 2016 and did not inform the Plan Sponsor of the incident before his departure. However, the Plan Sponsor was able to confirm the second unauthorized recipient deleted the email prior to leaving his employment and that the email was not forwarded. The Organization received confirmation from the two unintended recipients on January 27, 2017 and January 30, 2017 respectively, that they deleted and did not forward or make a copy of the information at issue.

File Type: pdf
Categories: 2018
Tags: Unauthorized access