The covered entity (CE), CareSource, reported that its business associate (BA) inadvertently mailed the protected health information (PHI) of 8,730 individuals to the wrong recipients. The PHI involved included names, clinical information, and diagnoses/conditions. The CE notified HHS, affected individuals, and the media. To mitigate this breach and prevent similar errors, the CE implemented additional administrative safeguards. OCR obtained assurances that the CE implemented the corrective actions noted.
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: organization to hhs · backfill source
2026-09-25 · records: 17 to 8730 · backfill source
2026-09-25 · disclosed: 2021-03-22 to 2020-11-11 · backfill source
2026-09-25 · summary: empty to The covered entity (CE), CareSource, reported that its business associate (BA) inadvertently mailed the protected health information (PHI) of 8,730 individuals to the wrong recipients. The PHI involved included names, clinical information, · backfill source