Skip to content

Merkle Direct Marketing

Disclosed Jan 11, 201016 years ago15,000 affectedConfirmed

Official notice

The covered entity's (CE) business associate (BA) mailed protected health information (PHI) of approximately 15,000 individuals to incorrect addresses due to an error in its quarterly address update process. The mailing contained demographic information, explanations of benefits, clinical information, and diagnoses. Upon discovery of the breach, the CE collected the returned mail and verified that it had not been delivered, and updated its HIPAA policies and procedures. Following OCR's investigation, the CE was able to recover all or nearly all of the misdirected envelopes.

What is known

People affected15,000 (as reported to HHS)
DisclosedJan 11, 2010
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Merkle Direct Marketing (Business Associate, MD)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJan 11, 201015,000
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Merkle Direct Marketing

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.