On February 20, 2017, one of BCBSMA’s employer accounts requested data on its current and past employees. BCBSMA erroneously emailed data about individuals who were not current or past employees of the account holder in an encrypted email. The emailed data contained protected health information (PHI) of 1,843 individuals, including names, addresses, birthdates, and social security numbers. On December 12, 2017, the employer used the incorrect data and sent letters to the listed individuals. After being informed by the individuals of the error, the account holder did not further re-disclose the PHI and it was destroyed. BCBSMA provided breach notification to HHS, affected individuals, and the media. OCR reviewed BCBSMA’s policies and procedures as they relate to this breach report, and they appear to comply with the Privacy, Security and Breach Notification Rules.