Tufts Associated Health Maintenance Organization
Disclosed Feb 16, 20188 years ago70,320 affectedConfirmed
A business associate (BA), Clarity Software Solutions, prepared a mailing of 70,320 member identification (ID) cards for Tufts Associated Health Maintenance Organization, the covered entity (CE). The member ID number was visible through the envelope window, in addition to the member’s name and address. Following the breach, the CE and BA revised their quality control procedures. The CE provided breach notification to HHS, the affected individuals, and the media. OCR’s investigation revealed that the CE and BA had a BA agreement in place at the time of the breach. OCR reviewed the BA agreement and determined that it appeared to comply with the requirements of the HIPAA Rules. OCR opened a separate review of the BA regarding this incident.
What is known
| People affected | 70,320 (as reported to HHS) |
|---|---|
| Disclosed | Feb 16, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Tufts Associated Health Maintenance Organization (Health Plan, MA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 16, 2018 | 70,320 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Tufts Associated Health Maintenance Organization