UPMC Health Plan
Disclosed Jul 2, 201511 years ago722 affectedConfirmed
An employee of the covered entity (CE), UPMC Health Plan, inadvertently sent an unsecure email with protected health information (PHI) to an incorrect, third-party email address. The breach included the electronic PHI of 722 individuals and included names, dates of birth, member identification numbers, phone numbers, types of insurance, and members' primary care providers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE retrained staff members. OCR reviewed UPMC Health Plan’s risk analysis to ensure compliance with the Security Rule and obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 722 (as reported to HHS) |
|---|---|
| Disclosed | Jul 2, 2015 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): UPMC Health Plan (Health Plan, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 2, 2015 | 722 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.