Skip to content

Blue Cross Blue Shield of Michigan

Disclosed Mar 17, 201511 years ago3,903 affectedConfirmed

Official notice

OCR opened an investigation of the covered entity (CE), Blue Cross Blue Shield of Michigan, after it reported that the protected health information (PHI) of 3,903 of its patients had been stolen for the purposes of identity fraud. The types of PHI disclosed included names, ages, genders, dates of birth, contract numbers, group names and numbers, and social security numbers. The CE provided breach notification to HHS, the media and affected individuals. Following the breach, the CE improved safeguards by masking social security numbers, removing members’ dates of birth, limiting search results to 25 records, and installing new printing devices that require employees to scan their coded badges when printing. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected3,903 (as reported to HHS)
DisclosedMar 17, 2015
AttackLost or stolen device
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMar 17, 20153,903
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Blue Cross Blue Shield of Michigan

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.