Skip to content

SimplyWell

Disclosed Jun 1, 20188 years ago597 affectedConfirmed

Official notice

SimplyWell, a sub-contractor business associate (BA), reported that one of its workforce members accidentally uploaded a file containing protected health information (PHI) of 597 individuals onto an online portal it maintained for a covered entity (CE). The file, which included names, dates of birth, and “non-smoker” status of the individuals, was potentially viewable by the CE’s members with access to the portal. The BA provided breach notification to HHS, affected individuals, and the media. OCR reviewed the BA's policies and procedures related to the incident and determined them to be consistent with the provisions of the Privacy and Security Rules. Following the breach, the BA retrained the involved workforce member on its policies and procedures and also sent reminders to its workforce members on its policies and procedures.

What is known

People affected597 (as reported to HHS)
DisclosedJun 1, 2018
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): SimplyWell (Business Associate, TX)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJun 1, 2018597
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about SimplyWell

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.