SEIU Local 32BJ, District 36 Building Operators Welfare Trust Fund
Disclosed Dec 21, 20187 years ago911 affectedConfirmed
An employee of Express Scripts, a business associate (BA), inadvertently sent an email intended for the covered entity (CE) to another multi-employer health and welfare fund. The breach included the protected health information (PHI) of 911 individuals, including names, telephone numbers, social security numbers, dates of birth, and prescription information. The CE provided breach notification to HHS, affected individuals, and the media and provided credit monitoring to individuals. Following the breach, the CE ensured that the BA retrained the responsible employee. Additionally, OCR reviewed the CE’s risk analysis to ensure compliance with the Security Rule. The CE no longer does business with the BA.
What is known
| People affected | 911 (as reported to HHS) |
|---|---|
| Disclosed | Dec 21, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): SEIU Local 32BJ, District 36 Building Operators Welfare Trust Fund (Health Plan, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 21, 2018 | 911 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about SEIU Local 32BJ, District 36 Building Operators Welfare Trust Fund