Back to the register

Blue Cross and Blue Shield of Oklahoma

ArchivedSubmitted 04/13/2025
State
IL
Covered entity type
Health Plan
Individuals affected
1,020
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Other
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Blue Cross and Blue Shield of Oklahoma, discovered fraudulent registration activity in its member portal system, Blue Access for Members, that affected the protected health information (PHI) of 1,020 individuals. The PHI involved included clinical, demographic, and financial information. The CE provided breach notification to the affected individuals, the media, the HHS Secretary, and posted substitute breach notice on their websites. In response to the breach, the CE provided complimentary credit monitoring services to the affected individuals, and implemented additional administrative, technical, and security safeguards to better protect its PHI.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.