Central States Southeast and Southwest Areas Health and Welfare Fund
Disclosed Jan 23, 20188 years ago634 affectedConfirmed
The covered entity (CE), Central States Southeast and Southwest Areas Health and Welfare Fund, mailed welcome and enrollment packets to incorrect addresses based on a mismatched employee list spreadsheet provided by the employer of a new group, Bemis. The breach affected approximately 634 individuals and included names, birthdates, social security numbers, plan election information, and dependent information. Following the breach, the CE provided breach notification to HHS, affected individuals, and the media. To prevent a similar breach from happening in the future, the CE revised its procedure for sending mailings to newly enrolled groups. Following OCR’s investigation, the CE agreed to change its privacy policies and procedures and agreed to develop a written policy related to fulfilling the requirements of the Breach Notification Rule.
What is known
| People affected | 634 (as reported to HHS) |
|---|---|
| Disclosed | Jan 23, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Central States Southeast and Southwest Areas Health and Welfare Fund (Health Plan, IL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jan 23, 2018 | 634 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Central States Southeast and Southwest Areas Health and Welfare Fund