Skip to content

Health Advantage

Disclosed Dec 20, 201213 years ago2,863 affectedConfirmed

Official notice

The covered entity (CE), Health Advantage, mailed Personal Health Statements to approximately 2,863 plan members’ previous addresses due to an internal programming error. This incident affected additional patients (addressed in separate breach reports) in that the covered entity had contracted with other covered entities, BCBS of Arkansas, the State of Arkansas Department of Finance and Administration Employee Benefits Division health plan and Baptist Health System’s health plan. The protected health information (PHI) involved in the breach included patients’ demographic information, health insurance identification numbers, descriptions of treatment or services received, and names of treating facilities or providers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE corrected the programming error, purged outdated information from its system, and implemented new quality control procedures for mailings. As a result of OCR’s investigation, Health Advantage also revised or entered into multiple business associate agreements.

What is known

People affected2,863 (as reported to HHS)
DisclosedDec 20, 2012
AttackNot stated
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Health Advantage (Health Plan, AR)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalDec 20, 20122,863

Other breaches at Health Advantage

BreachAffected
Disclosed Aug 25, 2022Aug 25, 20224 years agoHacking1,642
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Health Advantage

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.