EnvisionRx
Disclosed Oct 23, 201510 years ago540 affectedConfirmed
Due to a processing error, the business associate (BA), EnvisionRx, mailed letters to the covered entity’s (CE) members that contained other members' protected health information (PHI). The names, medications, and dates of service of 540 individuals were involved in the breach. The BA provided breach notification to HHS, affected individuals, and the media. The BA responded to the breach by implementing additional quality control procedures, updating its Breach Rule Notification policy, and training the appropriate staff. As a result of OCR’s investigation the BA updated it BA agreement with the CE, Orange-Ulster School District Health Plan. The BA also provided OCR with documentation of its corrective actions.
What is known
| People affected | 540 (as reported to HHS) |
|---|---|
| Disclosed | Oct 23, 2015 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): EnvisionRx (Business Associate, OH)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 23, 2015 | 540 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.