Back to the register

UnitedHealthcare Community Plan of Pennsylvania

ArchivedSubmitted 12/27/2017
State
PA
Covered entity type
Business Associate
Individuals affected
614
Business associate present
Yes
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On October 16, 2017, a third-party subcontractor of the covered entity (CE), United Healthcare Community Plan, erroneously prepared and mailed a letter (intended for numerous physicians) to 614 health plan members. These letters contained protected health information (PHI) about certain plan members including names, addresses, plan identification numbers, telephone numbers, provider names, and it inferred that a diabetes condition was associated with the member. The CE believed that the errant letters were addressed in such a way that none were deliverable and would either be destroyed by the US Postal Service (USPS) or potentially returned to the company as undeliverable. On November 1, 2017, the CE indicated that it received a call from a member recipient that they received one of these errant letters. The CE received a total of nine of such reports. The CE believed that most of the letters were destroyed by the USPS as undeliverable; however, in an abundance of caution they provided breach notification to all 614 members whose PHI was included in the mailing, in addition to notifying HHS. The CE strengthened safeguards by requiring an additional quality review prior to the release of mailings to the USPS and by limiting the use of third-party subcontractors in the future to mailing jobs that do not contain PHI or personally identifiable information (PII). Additionally, mailings that contain PHI or PII will use a USPS Return Service. OCR reviewed a copy of the relevant signed business associate agreement and the CE’s current risk assessment. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.