Skip to content

EnvisionRx

Disclosed Oct 23, 201510 years ago540 affectedConfirmed

Official notice

Due to a processing error, the business associate (BA), EnvisionRx, mailed letters to the covered entity’s (CE) members that contained other members' protected health information (PHI). The names, medications, and dates of service of 540 individuals were involved in the breach. The BA provided breach notification to HHS, affected individuals, and the media. The BA responded to the breach by implementing additional quality control procedures, updating its Breach Rule Notification policy, and training the appropriate staff. As a result of OCR’s investigation the BA updated it BA agreement with the CE, Orange-Ulster School District Health Plan. The BA also provided OCR with documentation of its corrective actions.

What is known

People affected540 (as reported to HHS)
DisclosedOct 23, 2015
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): EnvisionRx (Business Associate, OH)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalOct 23, 2015540
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about EnvisionRx

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.