Back to the register

DePaul University

ArchivedSubmitted 12/21/2018
State
IL
Covered entity type
Health Plan
Individuals affected
656
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On December 14, 2018, a DePaul University employee inadvertently sent an email to participants in its health plan’s wellness program without blind copying the email recipients. This allowed the names of 656 individuals to be visible to other recipients of the email. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE send an email to recipients requesting that they delete the erroneous email, counseled and educated the employee who sent the email, and provided HIPAA refresher training to the benefits staff. The CE also implemented a new process to automate blind copying of recipients for any group email distribution or notices related to the CE's health and welfare benefits plan. OCR obtained documented assurances that the CE implemented these corrective action steps.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.