Back to the register

New York City Human Resources Administration/Department of Social Services

ArchivedSubmitted 05/11/2018
State
NY
Covered entity type
Health Plan
Individuals affected
2,078
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

From January 1, 2017 to March 13, 2018, an internal programming error in the mailing system for Medicaid renewal forms may have caused forms to be mailed to the wrong post office box addresses, affecting 2135 individuals. The types of protected health information (PHI) on the forms included Medicaid clients’ names, other household members’ names, addresses, clients’ dates of birth and other household members’ dates of birth, clients' identification numbers (a unique Medicaid case number), household compensation, resources, and income information. The CE provided breach notification to HHS, the media, and the affected individuals, and posted notice to its website. Following the breach, the CE determined that the programming error occurred because of an unintended electronic interaction of the various systems used in the mailing process and deployed a technical fix. To mitigate any potential harmful effects on Medicaid beneficiaries, the CE re-opened any case that closed in 2018 for failure to return the Medicaid renewal form, and provided such clients with instructions for seeking reimbursement for medical bills incurred after their Medicaid coverage ended. For those affected individuals whose recertification period had not ended, the CE extended the eligibility period, so new Medicaid renewal forms could be sent to them. OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, the CE is expected to mail individual notification letters to the 57 affected individuals identified after the CE filed its initial breach report, which had reported 2,078 affected individuals.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.