Skip to content

Windsor Health Plan

Disclosed Jul 22, 201115 years ago1,378 affectedConfirmed

Official notice

A third-line sub-contractor of Windsor Health Plan’s business associate (BA), CVS Caremark, changed the printing format on letters mailed to the covered entity’s (CE) members, potentially causing protected health information (PHI) to be visible through the envelope window. The letters included the names, addresses, and some clinical information of 1,378 individuals. RxAmerica, an operating subsidiary of CVS Caremark, subcontracted its mailing services to Accendo, who in turn subcontracted printing services to Progressive Direct Mail (PDM). The CE provided breach notification to HHS and affected individuals; media notification did not occur because the impacted members did not exceed 500 in any single state or geographic area. However, CVS issued a media release regarding the incident. In response to the incident, Accendo conducted a full review of the incident, notified PDM of the formatting error, and ensured it was corrected. Accendo also conducted an onsite visit at the PDM facility and implemented new quality assurance protocols and internal validation steps. OCR obtained written assurances the CE provided the breach notification as indicated above.

What is known

People affected1,378 (as reported to HHS)
DisclosedJul 22, 2011
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Windsor Health Plan (Business Associate, TN)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJul 22, 20111,378
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Windsor Health Plan

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.