Blue Cross Blue Shield of North Carolina
Disclosed Sep 11, 201511 years ago1,530 affectedConfirmed
The covered entity (CE), Blue Cross Blue Shield of North Carolina, discovered on August 14, 2015, that its business associate (BA), EDM Americas, had accidently sent invoices to members that contained information for other members, affecting 1,530 individuals. The types of protected health Information (PHI) in the invoice included member names, addresses, internal account numbers, group numbers, coverage dates, and premium amounts due. The CE provided breach notification to HHS, on its website and to the media. The BA sent individual notification on behalf of the CE. In response to the breach, the BA retrained its staff and revised its internal validation and quality control procedures. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 1,530 (as reported to HHS) |
|---|---|
| Disclosed | Sep 11, 2015 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Blue Cross Blue Shield of North Carolina (Health Plan, NC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 11, 2015 | 1,530 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.