SimplyWell
Disclosed Jun 1, 20188 years ago597 affectedConfirmed
SimplyWell, a sub-contractor business associate (BA), reported that one of its workforce members accidentally uploaded a file containing protected health information (PHI) of 597 individuals onto an online portal it maintained for a covered entity (CE). The file, which included names, dates of birth, and “non-smoker” status of the individuals, was potentially viewable by the CE’s members with access to the portal. The BA provided breach notification to HHS, affected individuals, and the media. OCR reviewed the BA's policies and procedures related to the incident and determined them to be consistent with the provisions of the Privacy and Security Rules. Following the breach, the BA retrained the involved workforce member on its policies and procedures and also sent reminders to its workforce members on its policies and procedures.
What is known
| People affected | 597 (as reported to HHS) |
|---|---|
| Disclosed | Jun 1, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): SimplyWell (Business Associate, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 1, 2018 | 597 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.