Back to the register
Colorado Department of Health Care Policy and Financing
ArchivedSubmitted 08/18/2015
- State
- CO
- Covered entity type
- Health Plan
- Individuals affected
- 1,622
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Between May 25, 2015 and July 5, 2015, the Governors’ Office of Technology, a business associate (BA), sent letters containing protected health information (PHI) on behalf of the covered entity (CE), the Colorado Department of Health Care Policy and Financing, to the wrong Medical Assistance Program clients due to a technical error in the BA’s computer system. The breach affected up to 3,537 individuals, and the types of PHI involved (which varied from household to household) included names, addresses, state identification numbers, Medicaid case numbers, employers’ names, amount of income, amount of approved Advanced Premium Tax Credit, approvals/denials for the Medical Assistance Program, and dates of birth. The CE provided breach notification to HHS, affected individuals, and the media. To prevent a recurrence of this type of incident, the BA’s subcontractor, Deloitte, fixed the software that is used for the Colorado Benefits Management System to ensure that the CE’s letters are addressed to the appropriate recipients, and implemented additional procedures for quality control of mailings. OCR obtained written assurances that the CE, BA and its subcontractor implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.