New Mexico Retiree Health Care Authority
Disclosed Oct 2, 20187 years ago586 affectedConfirmed
On September 27, 2018, the covered entity (CE), New Mexico Retiree Health Care Authority, mailed a summary of benefits packets to approximately 586 members, including the members’ names, lists of dependents, and the last four digits of their social security numbers, to the wrong address as a result of human error. To mitigate the impermissible disclosures, the CE implemented appropriate safeguards and updated its HIPAA policies and training. The CE provided breach notification to HHS and affected individuals and provided individuals with free credit monitoring. OCR obtained assurances that the CE implemented the corrective action steps listed above.
What is known
| People affected | 586 (as reported to HHS) |
|---|---|
| Disclosed | Oct 2, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): New Mexico Retiree Health Care Authority (Health Plan, NM)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 2, 2018 | 586 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.