BlueCross BlueShield of Western New York
Disclosed Jan 22, 201313 years ago725 affectedConfirmed
The covered entity’s (CE) business associate (BA), Blue Cross Blue Shield, mailed a monthly premium notice with invoices that contained the protected health information (PHI) of 725 individuals which was never received by the CE. The PHI included names, member identification numbers, and social security numbers. Upon discovery of the breach, the BA contacted the U.S. Post Office regarding the undelivered mailing. The CE provided breach notification to HHS and the BA notified affected individuals. The BA revised its invoice procedures to assure the removal of social security numbers and member identification numbers, and send invoices via secure email. The breach incident involved a BA and occurred prior to the September 23, 2013, compliance date. OCR verified that the CE had a proper BA agreement in place that restricted the BA’s use and disclosure of PHI and required the BA to safeguard all PHI.
What is known
| People affected | 725 (as reported to HHS) |
|---|---|
| Disclosed | Jan 22, 2013 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): BlueCross BlueShield of Western New York (Business Associate, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jan 22, 2013 | 725 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.