Back to the register
SEIU Local 32BJ, District 36 Building Operators Welfare Trust Fund
ArchivedSubmitted 12/21/2018
- State
- PA
- Covered entity type
- Health Plan
- Individuals affected
- 911
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An employee of Express Scripts, a business associate (BA), inadvertently sent an email intended for the covered entity (CE) to another multi-employer health and welfare fund. The breach included the protected health information (PHI) of 911 individuals, including names, telephone numbers, social security numbers, dates of birth, and prescription information. The CE provided breach notification to HHS, affected individuals, and the media and provided credit monitoring to individuals. Following the breach, the CE ensured that the BA retrained the responsible employee. Additionally, OCR reviewed the CE’s risk analysis to ensure compliance with the Security Rule. The CE no longer does business with the BA.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.