Back to the register
Tufts Associated Health Maintenance Organization, Inc.
ArchivedSubmitted 02/16/2018
- State
- MA
- Covered entity type
- Health Plan
- Individuals affected
- 70,320
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A business associate (BA), Clarity Software Solutions, prepared a mailing of 70,320 member identification (ID) cards for Tufts Associated Health Maintenance Organization, the covered entity (CE). The member ID number was visible through the envelope window, in addition to the member’s name and address. Following the breach, the CE and BA revised their quality control procedures. The CE provided breach notification to HHS, the affected individuals, and the media. OCR’s investigation revealed that the CE and BA had a BA agreement in place at the time of the breach. OCR reviewed the BA agreement and determined that it appeared to comply with the requirements of the HIPAA Rules. OCR opened a separate review of the BA regarding this incident.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.