The covered entity, Health Net, Inc. (HN), erroneously mailed identification cards for 8,331 members to their former addresses due to a system error by its contractor, Cognizant Technology Services. HN also acts as a business associate for some other covered entities. The types of protected health information (PHI) included demographic information, such as members’ names. HN provided breach notification to HHS, affected individuals, and the media. Following the breach, HN uncovered and corrected the programming error and developed and implemented a new program to help ensure that the syncing of beneficiary addresses between specific enrollment files and HN’s master address file is accurate. OCR provided technical assistance regarding security risk analysis and determined that HN must conduct an enterprise-wide security risk analysis..
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 8331 · backfill source
2026-09-25 · disclosed: 2013-08-01 to 2013-07-02 · backfill source
2026-09-25 · summary: empty to The covered entity, Health Net, Inc. (HN), erroneously mailed identification cards for 8,331 members to their former addresses due to a system error by its contractor, Cognizant Technology Services. HN also acts as a business associate for · backfill source