DisclosureLens
TENNESSEEAccidentalHealthcareHealthcareMisdeliveryBusiness Associate (HIPAA)Customer Data InvolvedPHIHealth (basic)Identity (basic)MediumResolved

BLUECROSS BLUESHIELD OF TENNESSEE, INC.

bd_3f0269588127535a · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 5, 2017

Filed

Jul 21, 2017

To disclose

16 days

Affected

2,117

Confidence

67%
Full breach record for BLUECROSS BLUESHIELD OF TENNESSEE, INC.11 incidents on file

BlueCross BlueShield of TN, Inc. reported to HHS on 2017-07-21 a Unauthorized Access/Disclosure affecting 2117 individuals. Breached information located on Paper/Films. The entity erroneously mailed a monthly report to employer health plan administrators that included the PHI of members enrolled in another group due to a software discrepancy.

HIPAA clock HHS report on time16 days discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

discovery → filing · 16 days

Jul 5, 2017

Discovered

Jul 21, 2017

Filed

vs. sector median

10 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,117 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.