Back to the register

Molina Healthcare

ArchivedSubmitted 12/21/2017
State
FL
Covered entity type
Health Plan
Individuals affected
1,380
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Other
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Molina Healthcare, Inc., the covered entity (CE), made an error when it prepared mailing lists for its business associate (BA), Merrill Communications, LLC, to use when it sent letters to Molina beneficiaries from October 13, 2017 through October 23, 2017. As a result of the error, when the BA sent the letters they were delivered to an incorrect beneficiary. The breach affected 1,380 individuals and the types of protected health information (PHI) listed in the letters included beneficiaries’ names, member identification numbers, dates of service, and the name of the beneficiaries’ physicians. The CE sent timely breach notification to HHS, the affected individuals, and the media. It also offered affected individuals 24 months of free identity theft protection. To mitigate the breach, the CE conducted an outreach campaign to collect copies of the misdirected mail and sanctioned and retrained the responsible employees. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.