Back to the register
Horizon Healthcare Services, Inc., doing business as Horizon Blue Cross Blue Shield of New Jersey, and its affiliates
ArchivedSubmitted 01/03/2014
- State
- NJ
- Covered entity type
- Business Associate
- Individuals affected
- 839,711
- Business associate present
- Yes
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Horizon Health Care Services, the covered entity (CE), reported that two unencrypted laptop computers were stolen from its Newark, NJ headquarters, affecting approximately 839,711 individuals. The types of protected health information (PHI) involved in the breach included names, dates of birth, insurance identification numbers, and in some instances social security numbers and/or clinical information. The CE provided breach notifications to HHS, affected individuals and the media. During the course of the investigation, the CE conducted a comprehensive inventory of all its computers containing PHI to ensure that they were fully encrypted, enhanced configuration settings on workstations to encrypt email containing electronic PHI, and disabled features on all devices that permitted exporting of data to removable storage media. It also implemented new procedures for information technology purchasing, decision-making and management, improved facility access controls, and retrained its workforce. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.