- State
- MA
- Covered entity type
- Health Plan
- Individuals affected
- 1,843
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On February 20, 2017, one of BCBSMA’s employer accounts requested data on its current and past employees. BCBSMA erroneously emailed data about individuals who were not current or past employees of the account holder in an encrypted email. The emailed data contained protected health information (PHI) of 1,843 individuals, including names, addresses, birthdates, and social security numbers. On December 12, 2017, the employer used the incorrect data and sent letters to the listed individuals. After being informed by the individuals of the error, the account holder did not further re-disclose the PHI and it was destroyed. BCBSMA provided breach notification to HHS, affected individuals, and the media. OCR reviewed BCBSMA’s policies and procedures as they relate to this breach report, and they appear to comply with the Privacy, Security and Breach Notification Rules.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.