- State
- IN
- Covered entity type
- Health Plan
- Individuals affected
- 610
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On March 13, 2016, a Customer Relationship Management (CRM) export file mismatched members to addresses causing communications to be sent to incorrect member addresses on a file dated February 24, 2016. This mismatched data was submitted to a print vendor to distribute New Member Packets and Identification (“ID”) cards. In addition, the covered entity (CE) sent the names, Medicaid ID numbers, and protected health information (PHI) of Indiana members to members in the CE's sister plan in the state of Ohio. Approximately 610 individuals were affected by the breach. Upon discovering the breach, the CE reported the breach incident to Indiana’s state regulators. The CE provided breach notification to HHS, affected individuals, and the media. To prevent similar breaches from happening in the future, The CE corrected the error in the export file and manually repopulated the voided bad address with accurate addresses. Additionally, the CE implemented new technical safeguards and improved quality assurance procedures for print mailings in order to confirm accuracy. The CE also trained the business analyst responsible for this breach matter and trained its workforce on its policies and procedures regarding Security Awareness. OCR obtained documented assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.