- State
- NC
- Covered entity type
- Health Plan
- Individuals affected
- 6,877
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), ABB Inc. Active Employee Group Benefit Plan, contracts with BlueAdvantage Administrators of Arkansas, a business associate (BA), to be a third party administrator for the CE’s medical plan for its U.S. employees. Due to a mailing error, the BA impermissibly disclosed the protected health information (PHI) of 6,877 plan members, including member names, ID numbers, and addresses. The CE provided breach notification to HHS and the media, and the BA provided individual notification. In order to prevent a similar mistake from happening in the future, the BA reviewed and made changes to its procedures and retrained staff. The BA also cancelled the member cards and ID numbers affected by the mailing, and issued new cards and ID numbers. OCR determined that the CE had a business associate agreement in place with the BA and obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.