TRUEbenefits
Disclosed Aug 14, 20179 years ago17,309 affectedConfirmed
An unauthorized person accessed an employee’s email account after it was compromised by a phishing incident and some of the emails accessible through the account contained electronic protected health information (ePHI). The breach affected approximately 17,309 individuals who were members of employer health plans administered by TRUEBenefits, LLC (TB). The PHI involved in the breach included demographic, financial, and clinical information. TB provided breach notification to HHS, covered entities, affected individuals, and the media in all 50 states and Puerto Rico, and also provided substitute notice. Upon discovery of the breach, TB immediately reset the employee’s password, disabled the loaner laptop the employee was using, and removed remote email access capabilities from the employee’s phone. In response to the breach, TB offered potentially affected individuals with two years of credit monitoring and made improvements to its ePHI systems’ data loss prevention and access rights management features. OCR obtained assurances that TB implemented the corrective actions noted above.
What is known
| People affected | 17,309 (as reported to HHS) |
|---|---|
| Disclosed | Aug 14, 2017 |
| Discovered | Jun 26, 2017 |
| Happened | May 18, 2017 |
| Attack | Phishing |
| Data exposed | Names, Social Security numbers, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: TRUEbenefitsoag.ca.gov · Official notice | Official notice |
| Washington Attorney General breach notice: TRUEbenefitsatg.wa.gov · Official notice | Official notice |
| Oregon DOJ breach notice: TRUEbenefitsjustice.oregon.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: TRUEbenefitsmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): TRUEbenefits (Business Associate, WA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Washington AGresidents of WA | Aug 14, 2017 | 12,327 |
| Maine AGresidents of ME | Aug 14, 2017 | 2 |
| HHS archivetotal | Aug 14, 2017 | 17,309 |
| California AGresidents of CA | Sep 18, 2017 | |
| Oregon DOJresidents of OR | Sep 18, 2017 | 20,476 |
| Maine AGresidents of ME | Sep 18, 2017 | 8 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 17309 · backfill source
- 2026-09-25 · summary: empty to An unauthorized person accessed an employee’s email account after it was compromised by a phishing incident and some of the emails accessible through the account contained electronic protected health information (ePHI). The breach affected · backfill source
- 2026-09-25 · data_types: [] to ["names","ssn"] · backfill source
- 2026-09-25 · attack: unknown to phishing · backfill source
- 2026-09-25 · disclosed: 2017-09-18 to 2017-08-14 · backfill source
- 2026-09-25 · discovered: empty to 2017-06-26 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.