- State
- MA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,146
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Between July 13, 2017 and October 1, 2017, the covered entity (CE), Alere Toxicology, mailed a number of health insurers using clear envelope address windows that displayed 2,146 patients’ protected health information (PHI), due to an employee error. The types of PHI involved in the breach included demographic and health claims information. The CE provided breach notification to HHS and the affected individuals and provided credit monitoring and placed a 90 day fraud alert on individuals’ credit files. Following the breach, the CE stopped using envelopes with clear windows for processing claims. Additionally, the CE implemented new quality controls for mailings and retrained employees at the facility where this incident. OCR obtained assurances that the CE implemented the corrective action steps noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.