- State
- PA
- Covered entity type
- Health Plan
- Individuals affected
- 732
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
As a result of a software error, a business associate (BA) misaddressed explanation of benefit (EOB) letters and they were delivered to persons other than the intended recipient. The breach affected approximately 732 individuals and the types of protected health information (PHI) included names, addresses, and clinical and diagnostic information. Breach notification was provided to HHS, affected individuals, and the media. Following the breach, the BA implemented a new audit process for mailings, and retrained staff members. OCR reviewed the CE's policies and procedures to ensure compliance with the Privacy and Security Rules.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.