Back to the register

SilverScript Insurance Company

ArchivedSubmitted 01/08/2013
State
AZ
Covered entity type
Health Plan
Individuals affected
852
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Letters for 852 prospective new members of the covered entity (CE), SilverScript Insurance Company Part D plan, were misdirected to incorrect addresses. SilverScript is a wholly-owned subsidiary of CVS Health, formerly CVS Caremark. The CE reported that the root cause of the incident was that the eligibility data file received from Northgate Arinso, a third party vendor of Energy Future Holdings, was inaccurate. The data file contained multiple, incorrect addresses, resulting in protected health information (PHI) being disclosed to other members. The letters contained members’ names, addresses, identification numbers, and group numbers and informed the members that such information could be taken to a pharmacy and used to process pharmacy claims. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, CVS Health implemented additional quality control measures to verify information received from third parties. OCR obtained and reviewed documentation regarding the implementation of those additional quality control measures.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.