- State
- OH
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,182
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On July 17, 2019, the CE forwarded mismatched member information to its business associate (BA), causing 1,182 members to receive mail that contained another member’s name and location of service. Following the CE’s internal investigation, the CE provided self-addressed stamp envelopes to facilitate the return of the incorrectly addressed letters, implemented a procedure to ensure that documents will be correctly formatted and saved in a format which cannot be changed, and implemented quality measures to ensure information is correct. The CE also completed execution of a renewal business associate agreement with its vendor. The CE provided breach notification to HHS, affected individuals, and the media. OCR obtained documented assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.