- State
- CA
- Covered entity type
- Health Plan
- Individuals affected
- 8,331
- Business associate present
- No
- Type of breach
- Other
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity, Health Net, Inc. (HN), erroneously mailed identification cards for 8,331 members to their former addresses due to a system error by its contractor, Cognizant Technology Services. HN also acts as a business associate for some other covered entities. The types of protected health information (PHI) included demographic information, such as members’ names. HN provided breach notification to HHS, affected individuals, and the media. Following the breach, HN uncovered and corrected the programming error and developed and implemented a new program to help ensure that the syncing of beneficiary addresses between specific enrollment files and HN’s master address file is accurate. OCR provided technical assistance regarding security risk analysis and determined that HN must conduct an enterprise-wide security risk analysis..
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.