After detecting malicious activity on its network, a large healthcare administration solutions provider discovered that sensitive personal information relating to its clients and their consumers had been accessed by an unauthorized party. Kroll’s elite Breach Notification specialists and proprietary technology enabled the seamless notification of data owners and affected individuals, helping to manage and minimize the business impact of the data breach.

Secure and Seamless Notification Following a Data Breach
Overview
Industry
- Healthcare
Challenges
- Exposure of highly sensitive benefit plan, insurance provider and customer data
- Complex monitoring requirements
- Lack of in-house notification and monitoring expertise
Kroll Services
- Breach Notification
Impact
- Notification of 100+ data owners and 3,340,000 impacted individuals
- Comprehensive reporting and record keeping
- Over 6,000 calls handled by a dedicated call center
- Accelerated regulatory compliance
The Challenge
A large healthcare administration company noted suspicious activity on its network. An investigation confirmed that an unauthorized party had accessed personal information related to benefit plans and insurance providers, as well as consumers. After identifying which providers and individuals were impacted, the business asked Kroll’s Breach Notification team for assistance.
Kroll’s Solution
Kroll was uniquely positioned to support the company through its third-party breach management platform, Kroll Notification Navigator (KNN). The platform enables a business to notify third party entities of a data breach, providing a secure space for them to access their unique data, review the proposed notification to consumers, speak to representatives knowledgeable about the breach and choose whether to opt in to the notification service.
The client trusted Kroll to handle the notification to the impacted third-party entities, provide secure access to the KNN portal and field calls and questions related to the breach. This allowed the business to maintain focus on its day-to-day operations in a high-pressure situation. The impacted third-party entities, benefit plan and insurance companies were then able to review their own data and opt in to the notification to customers being managed without taking on the burden of doing so out of pocket.
The Impact
Unparalleled Insight
Kroll’s end-to-end breach notification services ensured that the client could provide essential insight to impacted organizations and individuals at every stage of the notification process. As well as regular status and reporting updates to keep track of progress in real-time, the company’s clients had access to data categorized by entity, final reports of notified individuals, monitoring activations, returned mail reports and final copies of notification letters.
Seamless Breach Notification
Kroll enabled the seamless notification of 130 data owners via email and mailed 3,346,000 notification letters to impacted individuals, with more than 71,000 people taking advantage of Kroll’s offer of credit monitoring for two years following the data breach.
Specialist Call Center Services
Ready to deliver frontline care for the company’s affected individuals right away, Kroll’s highly skilled, multilingual customer support team managed 6,640 calls relating to the incident. This was backed with access to Kroll’s licensed investigators, at the ready to answer individuals’ questions about identity theft and assist with personalized safeguards to reduce the potential financial impact of unauthorized use of lost or exposed data.
Swift Regulatory and Legal Compliance
Kroll’s assistance sped up the process of gathering opt-in decisions, Office of Civil Rights and other substitute notice filings, ensuring that the company met all its regulatory obligations.
Stay Ahead with Kroll
Cyber and Data Resilience
Kroll merges elite security and data risk expertise with frontline intelligence from thousands of incident responses and regulatory compliance, financial crime and due diligence engagements to make our clients more cyber- resilient.
Data Breach Notification Services
Kroll’s data breach notification, call centers and monitoring team brings global breach response expertise to efficiently manage regulatory and reputational needs.
Breach Notification
Kroll’s data breach notification solutions – from drafting compliant letters, to full-service mailing help, to alternate notifications for large breaches – take the burden off your organization.
Data Breach Notification Letters
Kroll will work with your team to implement a personalized, plain-language notification letter that provides pertinent information and maintains message control.
Identity Theft Restoration
Kroll provides your breach population with direct access to investigative experts for live support and best practice advice, as well as identity restoration should they become victims of identity theft.
Identity Monitoring
Kroll’s unique combination of identity monitoring services can detect more types of identity theft than credit monitoring alone, providing practical help to combat identity theft and fraud.

