Skip to content

TRUEbenefits

Disclosed Aug 14, 20179 years ago17,309 affectedConfirmed

Official notice

An unauthorized person accessed an employee’s email account after it was compromised by a phishing incident and some of the emails accessible through the account contained electronic protected health information (ePHI). The breach affected approximately 17,309 individuals who were members of employer health plans administered by TRUEBenefits, LLC (TB). The PHI involved in the breach included demographic, financial, and clinical information. TB provided breach notification to HHS, covered entities, affected individuals, and the media in all 50 states and Puerto Rico, and also provided substitute notice. Upon discovery of the breach, TB immediately reset the employee’s password, disabled the loaner laptop the employee was using, and removed remote email access capabilities from the employee’s phone. In response to the breach, TB offered potentially affected individuals with two years of credit monitoring and made improvements to its ePHI systems’ data loss prevention and access rights management features. OCR obtained assurances that TB implemented the corrective actions noted above.

What is known

People affected17,309 (as reported to HHS)
DisclosedAug 14, 2017
DiscoveredJun 26, 2017
HappenedMay 18, 2017
AttackPhishing
Data exposedNames, Social Security numbers, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: TRUEbenefitsoag.ca.gov · Official notice
Washington Attorney General breach notice: TRUEbenefitsatg.wa.gov · Official notice
Oregon DOJ breach notice: TRUEbenefitsjustice.oregon.gov · Official notice
Maine Attorney General breach notice archive: TRUEbenefitsmaine.gov · Official notice
HHS OCR breach report (archive, resolved): TRUEbenefits (Business Associate, WA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Washington AGresidents of WAAug 14, 201712,327
Maine AGresidents of MEAug 14, 20172
HHS archivetotalAug 14, 201717,309
California AGresidents of CASep 18, 2017
Oregon DOJresidents of ORSep 18, 201720,476
Maine AGresidents of MESep 18, 20178
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 17309 · backfill source
  • 2026-09-25 · summary: empty to An unauthorized person accessed an employee’s email account after it was compromised by a phishing incident and some of the emails accessible through the account contained electronic protected health information (ePHI). The breach affected · backfill source
  • 2026-09-25 · data_types: [] to ["names","ssn"] · backfill source
  • 2026-09-25 · attack: unknown to phishing · backfill source
  • 2026-09-25 · disclosed: 2017-09-18 to 2017-08-14 · backfill source
  • 2026-09-25 · discovered: empty to 2017-06-26 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about TRUEbenefits

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.