Skip to content

Blue Cross & Blue Shield of Rhode Island

Disclosed Sep 13, 20188 years ago1,567 affectedConfirmed

Official notice

RedCard, a business associate (BA) that provides mailing services to Blue Cross & Blue Shield of Rhode Island, the covered entity (CE), impermissibly disclosed protected health information (PHI) when it improperly consolidated explanations of benefits (EOB) in mailings, causing EOB documents for different individuals who resided at the same address (i.e., family members) to be mailed together. The breach affected the PHI of 1,567 individuals and included names, plan identification numbers, healthcare provider’s names, types of medical service provided, and claim information. Following the breach, the BA ceased consolidating EOBs. The CE provided breach notification to HHS, the media, and the affected individuals. OCR reviewed the CE’s BA agreement with the BA and it appeared to be in compliance with the Privacy Rule.

What is known

People affected1,567 (as reported to HHS)
DisclosedSep 13, 2018
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalSep 13, 20181,567

Other breaches at Blue Cross & Blue Shield of Rhode Island

BreachAffected
Disclosed Apr 21, 2010Apr 21, 201016 years agoLost or stolen device12K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Blue Cross & Blue Shield of Rhode Island

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.