Alere Toxicology
Disclosed Nov 28, 20178 years ago2,146 affectedConfirmed
Between July 13, 2017 and October 1, 2017, the covered entity (CE), Alere Toxicology, mailed a number of health insurers using clear envelope address windows that displayed 2,146 patients’ protected health information (PHI), due to an employee error. The types of PHI involved in the breach included demographic and health claims information. The CE provided breach notification to HHS and the affected individuals and provided credit monitoring and placed a 90 day fraud alert on individuals’ credit files. Following the breach, the CE stopped using envelopes with clear windows for processing claims. Additionally, the CE implemented new quality controls for mailings and retrained employees at the facility where this incident. OCR obtained assurances that the CE implemented the corrective action steps noted above.
What is known
| People affected | 2,146 (as reported to HHS) |
|---|---|
| Disclosed | Nov 28, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Alere Toxicology (Healthcare Provider, MA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 28, 2017 | 2,146 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.