Skip to content

DePaul University

Disclosed Dec 21, 20187 years ago656 affectedConfirmed

Official notice

On December 14, 2018, a DePaul University employee inadvertently sent an email to participants in its health plan’s wellness program without blind copying the email recipients. This allowed the names of 656 individuals to be visible to other recipients of the email. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE send an email to recipients requesting that they delete the erroneous email, counseled and educated the employee who sent the email, and provided HIPAA refresher training to the benefits staff. The CE also implemented a new process to automate blind copying of recipients for any group email distribution or notices related to the CE's health and welfare benefits plan. OCR obtained documented assurances that the CE implemented these corrective action steps.

What is known

People affected656 (as reported to HHS)
DisclosedDec 21, 2018
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): DePaul University (Health Plan, IL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalDec 21, 2018656
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about DePaul University

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.