- State
- NY
- Covered entity type
- Health Plan
- Individuals affected
- 6,231
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Amida Care, the covered entity (CE), sent double-sided flyers to 6,231 of its active members via postal mail that may have had the term "HIV" visible through the window envelopes and protective sheet. The CE provided breach notification to HHS, the media and affected individuals. Following the breach, the CE developed a policy and procedure to ensure that production and preparation of member mailings meets HIPAA compliance requirements and protects members privacy, provided training to workforce members responsible for member mailings, and held a series of meetings and communicated with its workforce about the nature, cause and extent of the breach in order to prevent reoccurrence. OCR obtained assurances that the CE implemented the corrective actions listed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.