Service Benefit Plan Administrative Services
Disclosed Dec 12, 20196 years ago11,536 affectedConfirmed
The covered entity (CE), Service Benefit Plan Administrative Services Corporation, reported that a programming error exposed the electronic protected health information (ePHI) of 11,536 individuals via its mobile application. The ePHI involved included names, addresses, health insurance information, claims information, financial data, treatment information, and medications prescribed. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE implemented additional administrative and technical safeguards to better protect its ePHI.
What is known
| People affected | 11,536 (as reported to HHS) |
|---|---|
| Disclosed | Dec 12, 2019 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Service Benefit Plan Administrative Services (Business Associate, DC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 12, 2019 | 11,536 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Service Benefit Plan Administrative Services