Mass General Brigham Health Plan
Disclosed Jun 28, 20242 years ago3,659 affectedConfirmed
Mass General Brigham Health Plan, the covered entity (CE), reported that an employee impermissibly shared her system credentials with an unauthorized individual in an effort to outsource her job duties. This breach affected the protected health information (PHI) of 3,659 individuals. The PHI involved included names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, Social Security numbers, health insurance and claims information, and diagnoses. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE provided complimentary credit monitoring services and established a call center for questions or concerns. In addition, the employee was sanctioned and all staff were retrained on the requirement to protect and secure sensitive data.
What is known
| People affected | 3,659 (as reported to HHS) |
|---|---|
| Disclosed | Jun 28, 2024 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Vermont Attorney General: 2024-06-28 Mass General Brigham Health Plan Data Breach Notice to Consumersago.vermont.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Mass General Brigham Health Plan (Health Plan, MA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Vermont AGresidents of VT | Jun 28, 2024 | |
| HHS archivetotal | Jun 28, 2024 | 3,659 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 3659 · backfill source
- 2026-09-25 · summary: empty to Mass General Brigham Health Plan, the covered entity (CE), reported that an employee impermissibly shared her system credentials with an unauthorized individual in an effort to outsource her job duties. This breach affected the protected he · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Vermont AG), confirmed by Vermont AG. Record counts are as reported. Not legal advice.