Blue Cross and Blue Shield of North Carolina
Disclosed Oct 11, 20187 years ago631 affectedConfirmed
In response to member telephone complaints, the covered entity (CE), Blue Cross Blue Shield of North Carolina, investigated and determined that on September 26, 2018, the CE mistakenly sent low income subsidy (LIS) letters to the wrong members due to an employee’s failure to follow established quality review procedures. Each letter contained the name and Blue Cross NC ID number for another member. Following the incident, the CE sanctioned the responsible staff member by coaching her and tasking her with creating a new process for sending the LIS letters. As a result of OCR’s investigation, the CE updated its policies and procedures by adopting the new process for mailing out the LIS letters. The CE also provided breach notification to HHS, affected individuals, and the media.
What is known
| People affected | 631 (as reported to HHS) |
|---|---|
| Disclosed | Oct 11, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Blue Cross and Blue Shield of North Carolina (Health Plan, NC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 11, 2018 | 631 |
Other breaches at Blue Cross and Blue Shield of North Carolina
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Aug 27, 2024Aug 27, 20242 years agoHacking | Aug 27, 20242 years ago | Hacking | Healthcare | Confirmed | 972 |
| Disclosed Nov 7, 2013Nov 7, 201312 years agoInsider | Nov 7, 201312 years ago | Insider | Insurance | Confirmed | 687 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Blue Cross and Blue Shield of North Carolina