Back to the register

Tufts Associated Health Maintenance Organization, Inc.

ArchivedSubmitted 02/16/2018
State
MA
Covered entity type
Health Plan
Individuals affected
70,320
Business associate present
Yes
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

A business associate (BA), Clarity Software Solutions, prepared a mailing of 70,320 member identification (ID) cards for Tufts Associated Health Maintenance Organization, the covered entity (CE). The member ID number was visible through the envelope window, in addition to the member’s name and address. Following the breach, the CE and BA revised their quality control procedures. The CE provided breach notification to HHS, the affected individuals, and the media. OCR’s investigation revealed that the CE and BA had a BA agreement in place at the time of the breach. OCR reviewed the BA agreement and determined that it appeared to comply with the requirements of the HIPAA Rules. OCR opened a separate review of the BA regarding this incident.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.