CareFirst Blue Cross Blue Shield
bd_47dd4c1058a72bed · schema v1 · pii pii-v1
Full breach record for CareFirst Blue Cross Blue Shield →5 incidents on fileCareFirst Blue Cross Blue Shield (MD) reported to HHS on 2018-04-26 a Hacking/IT Incident affecting 6,200 individuals. An employee was the victim of an email phishing attack that exposed ePHI including names, dates of birth, Social Security numbers, and health insurance information. Breached information was located in Email. The CE notified HHS and affected individuals, implemented additional technical safeguards, and retrained staff on recognizing fraudulent emails. OCR obtained assurances of corrective action.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Apr 26, 2018
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.