BlueCross BlueShield of South Carolina
Disclosed Feb 12, 201610 years ago998 affectedConfirmed
A business associate (BA), BlueCross\BlueShield, of the covered entity (CE), South Carolina Public Employee Benefit Authority, incorrectly mailed pre-authorization dental letters to the CE’s members due to a computer error. During the mailing sorting process, the names of the envelopes were not matched to the correct addresses. The breach affected 998 individuals and included financial, demographic, and clinical information. The BA provided breach notification to HHS, affected individuals, and the media. Following the breach, the BA revised its procedures for ensuring data integrity and accuracy and enhanced procedures to include a quality control validation step. The BA trained systems support staff and confirmed that it requires all of its employees, contractors and consultants employed or retained for longer than 45 days to receive HIPAA training. OCR obtained assurances that the BA implemented the corrective actions listed above.
What is known
| People affected | 998 (as reported to HHS) |
|---|---|
| Disclosed | Feb 12, 2016 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): BlueCross BlueShield of South Carolina (Business Associate, SC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 12, 2016 | 998 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.