Blue Cross and Blue Shield of North Carolina
Disclosed Nov 7, 201312 years ago687 affectedConfirmed
On October 14, 2013, the covered entity (CE), Blue Cross Blue Shield of North Carolina, impermissibly disclosed the protected health information (PHI) of 687 individuals when an employee inadvertently mailed notices regarding policy changes to incorrect addresses. The PHI involved in the breach included names. The CE provided breach notification to HHS and affected individuals. Following the breach the CE sanctioned the responsible workforce member. As a result of OCR’s investigation, the CE provided media notice and established a toll-free number for affected individuals. Additionally, the CE improved safeguards by retraining employees and initiating a regular review of mailing procedures.
What is known
| People affected | 687 (as reported to HHS) |
|---|---|
| Disclosed | Nov 7, 2013 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Blue Cross and Blue Shield of North Carolina (Health Plan, NC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 7, 2013 | 687 |
Other breaches at Blue Cross and Blue Shield of North Carolina
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Aug 27, 2024Aug 27, 20242 years agoHacking | Aug 27, 20242 years ago | Hacking | Healthcare | Confirmed | 972 |
| Disclosed Oct 11, 2018Oct 11, 20187 years agoInsider | Oct 11, 20187 years ago | Insider | Insurance | Confirmed | 631 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Blue Cross and Blue Shield of North Carolina