BeneSys
Disclosed Aug 10, 20206 years ago1,070 affectedConfirmed
BeneSys, the business associate (BA), reported that an employee inadvertently emailed documents containing the electronic protected health information (ePHI) of 1,070 individuals to the wrong recipient. The ePHI involved included names, Social Security numbers, and financial information. The BA notified HHS, affected individuals, and provided complimentary credit monitoring services to those affected by the breach. In its mitigation efforts, the BA sanctioned the responsible employee, implemented additional administrative safeguards, and retrained its staff. OCR obtained assurances that the BA implemented the corrective actions noted.
What is known
| People affected | 1,070 (as reported to HHS) |
|---|---|
| Disclosed | Aug 10, 2020 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): BeneSys (Business Associate, MI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 10, 2020 | 1,070 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.